CVE-2025-6543

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

History

01 Jul 2025, 18:19

Type Values Removed Values Added
CPE cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
First Time Citrix netscaler Gateway
Citrix netscaler Application Delivery Controller
Citrix
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788 - () https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788 - Vendor Advisory

26 Jun 2025, 18:57

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de desbordamiento de memoria que provoca un flujo de control no deseado y una denegación de servicio en NetScaler ADC y NetScaler Gateway cuando se configuran como Gateway (servidor virtual VPN, proxy ICA, CVPN, proxy RDP) O servidor virtual AAA

25 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-25 13:15

Updated : 2025-07-01 18:19


NVD link : CVE-2025-6543

Mitre link : CVE-2025-6543

CVE.ORG link : CVE-2025-6543


JSON object : View

Products Affected

citrix

  • netscaler_gateway
  • netscaler_application_delivery_controller
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer