CVE-2025-5777
17.06.2025, 13:15
Insufficient input validation leading to memory overread when theNetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual serverEnginsight
Vendor | Product | Version |
---|---|---|
citrix | netscaler_application_delivery_controller | 12.1 ≤ 𝑥 < 12.1-55.328 |
citrix | netscaler_application_delivery_controller | 13.1 ≤ 𝑥 < 13.1-37.235 |
citrix | netscaler_application_delivery_controller | 13.1 ≤ 𝑥 < 13.1-37.235 |
citrix | netscaler_application_delivery_controller | 13.1 ≤ 𝑥 < 13.1-58.32 |
citrix | netscaler_application_delivery_controller | 14.1 ≤ 𝑥 < 14.1-43.56 |
citrix | netscaler_gateway | 13.1 ≤ 𝑥 < 13.1-58.32 |
citrix | netscaler_gateway | 14.1 ≤ 𝑥 < 14.1-43.56 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-125 - Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.
- CWE-908 - Use of Uninitialized ResourceThe software uses or accesses a resource that has not been initialized.
- CWE-457 - Use of Uninitialized VariableThe code uses a variable that has not been initialized, leading to unpredictable or unintended results.
References