PT-2025-34761 · Citrix · Netscaler Adc +1
Published
2025-08-26
·
Updated
2025-08-27
·
CVE-2025-7775
9.8
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
NetScaler ADC and NetScaler Gateway versions 13.1, 14.1, 13.1-FIPS and NDcPP
**Description:**
A memory overflow vulnerability exists in NetScaler ADC and NetScaler Gateway, potentially leading to Remote Code Execution (RCE) and/or Denial of Service (DoS). This vulnerability is actively exploited in the wild, with exploitation observed on unmitigated appliances. The vulnerability is present when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, or when LB virtual servers of type (HTTP, SSL or HTTP QUIC) are bound with IPv6 services or servicegroups bound with IPv6 servers, or when LB virtual servers of type (HTTP, SSL or HTTP QUIC) are bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers, or with CR virtual server with type HDX.
**Recommendations:**
Versions prior to the latest available updates are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Buffer Overflow
Weakness Enumeration
Related Identifiers
Affected Products
References · 116
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7775 · Security Note
- https://twitter.com/oxhak/status/1960470010607870347 · Twitter Post
- https://twitter.com/trubetech/status/1960748556525982086 · Twitter Post
- https://twitter.com/DefendOpsHQ/status/1960756912666107953 · Twitter Post
- https://twitter.com/SimoKohonen/status/1960588379768172666 · Twitter Post
- https://twitter.com/cyntelnext/status/1960422293106016646 · Twitter Post
- https://twitter.com/CIDC_Ops/status/1960685922196054322 · Twitter Post
- https://twitter.com/zeeshankghouri/status/1960575963433197627 · Twitter Post
- https://twitter.com/f1tym1/status/1960438196300292525 · Twitter Post
- https://twitter.com/TechStackQueen/status/1960579420252483882 · Twitter Post
- https://twitter.com/YorickReintjens/status/1960398070522503653 · Twitter Post
- https://twitter.com/fridaysecurity/status/1960360475629121944 · Twitter Post
- https://twitter.com/Art_Capella/status/1960679533679665545 · Twitter Post
- https://twitter.com/fridaysecurity/status/1960337251868582351 · Twitter Post