NetScaler ADC and NetScaler Gateway Multiple Vulnerabilities (CTX693420)

critical Nessus Plugin ID 240341

Synopsis

The remote device may be affected by multiple vulnerabilities.

Description

The remote NetScaler ADC (formerly Citrix ADC) or NetScaler Gateway (formerly Citrix Gateway) device is version 12.1 before 12.1-55.328 (12.1-FIPS) or 13.1 before 13.1-37.235 (13.1-FIPS) or 13.1 before 13.1-58.32 or 14.1 before  14.1-43.56. It is, therefore, affected by multiple vulnerabilities:

- Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway (CVE-2025-5349)
- Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADC and NetScaler Gateway (CVE-2025-5777)

Please refer to advisory CTX693420 for more information.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to version 12.1-55.328 (12.1-FIPS), 13.1-37.235 (13.1-FIPS), 13.1-58.32, 14.1-43.56 or later.

See Also

http://www.nessus.org/u?43b55ab5

Plugin Details

Severity: Critical

ID: 240341

File Name: netscaler_adc_gateway_CTX693420.nasl

Version: 1.1

Type: combined

Family: CGI abuses

Published: 6/25/2025

Updated: 6/25/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Vulnerability Information

CPE: cpe:/h:citrix:netscaler_gateway, cpe:/h:citrix:netscaler_application_delivery_controller

Required KB Items: Host/NetScaler/Detected

Patch Publication Date: 6/17/2025

Vulnerability Publication Date: 6/17/2025

Reference Information

CVE: CVE-2025-5349, CVE-2025-5777