Cloud Software Group has issued an emergency security bulletin (CTX693420) addressing two critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway.
These flaws, tracked as CVE-2025-53 (CVSSv4 8.7) and CVE-2025-5777 (CVSSv4 9.3), expose organizations to unauthorized access and memory exploitation risks.
Here’s a breakdown of the threats and remediation steps.
CVE-2025-5349: Improper Access Control
CVE-2025-5777: Memory Overread via Input Validation Flaw
| CVE ID | Risk Factor | CVSSv4 | Severity | Preconditions | CWE |
|---|---|---|---|---|---|
| CVE-2025-5349 | Unauthorized Access | 8.7 | High | Access to NSIP/Cluster IP | CWE-284 |
| CVE-2025-5777 | Memory Exploitation | 9.3 | Critical | Gateway/AAA configuration | CWE-125 |
The vulnerabilities’ impact:
Critical Note:
Cloud Software Group mandates immediate action:
kill icaconnection -all kill pcoipConnection -all Execute these commands across all high-availability (HA) pairs or clusters.Discovery and Credits:
The vulnerabilities were reported by Positive Technologies and ITA MOD CERT (CERTDIFESA) through coordinated disclosure.
Ongoing Risks:
Unpatched systems face imminent threats of credential theft, data exfiltration, and hypervisor compromise, especially in virtualized environments.
Organizations must prioritize updates to avoid operational disruptions and regulatory penalties.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
The post Citrix NetScaler ADC and Gateway Vulnerabilities Expose Sensitive Data to Attackers appeared first on Cyber Security News.
Witch Hat Atelier is a great manga for newcomers to the medium, and the price…
BIG COUNTRY, Texas (KTAB/KRBC) – The Storm Prediction Center has placed nearly the entire Big…
ABILENE, Texas (KTAB/KRBC) - McMurry University has launched Abilene’s only collegiate gymnastics program. The program…
COLEMAN, Texas (KTAB/KRBC) - As the City of Coleman gets ready to celebrate its 150th…
ABILENE, Texas (KTAB/KRBC) - A new pickleball complex proposed in north Abilene has been given…
Editor’s Note: The Abilene Police Department supplied the following arrest and incident reports. All information…
This website uses cookies.