Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
(OR)
NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers
(OR)
NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers
(OR)
CR virtual server with type HDX
References
Link | Resource |
---|---|
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
27 Aug 2025, 14:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 - Vendor Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* |
|
First Time |
Citrix netscaler Gateway
Citrix netscaler Application Delivery Controller Citrix |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
26 Aug 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-26 13:15
Updated : 2025-08-27 14:26
NVD link : CVE-2025-7775
Mitre link : CVE-2025-7775
CVE.ORG link : CVE-2025-7775
JSON object : View
Products Affected
citrix
- netscaler_application_delivery_controller
- netscaler_gateway
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer