Junglewise Threat Intelligence

CVE-2025-5777: Citrix NetScaler ADC and Gateway out-of-bounds read

CVE-2025-5777 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2025-07-10

Executive brief

Citrix NetScaler ADC and Gateway appliances, which are used to manage network traffic and provide secure remote access, contain a critical security flaw. This vulnerability allows an attacker to read sensitive information from the device's memory without needing a password. This could lead to the theft of session tokens or other private data, potentially allowing unauthorized access to corporate networks. This issue is actively being exploited in the wild.

Technical details

An out-of-bounds read vulnerability exists in Citrix NetScaler ADC and Gateway due to insufficient input validation. The flaw is triggered when the device is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the appliance, leading to a memory overread. This can result in the disclosure of sensitive information, such as session cookies or memory-resident secrets, similar to the 'Citrix Bleed' vulnerability. Citrix has released security updates to address this issue, and CISA has confirmed active exploitation.

Affected products

  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway

Timeline

  • 2025-07-10: disclosed
  • 2025-07-10: advisory
  • 2025-07-10: kev added: Added to CISA KEV catalog due to active exploitation.
  • 2025-07-10: exploited

Related threats