Citrix NetScaler Gateway / ADC Memory Disclosure

critical Web App Scanning Plugin ID 114907

Synopsis

Citrix NetScaler Gateway / ADC Memory Disclosure

Description

Citrix NetScaler Gateway / ADC versions 14.1.x < 14.1-43.56, 13.1.x < 13.1-58.32, 13.1.x-FIPS < 13.1-37.235-FIPS and NDcPP, 12.1.x-FIPS < 12.1-55.328-FIPS, 12.1.x and 13.0.x are affected by a memory disclosure vulnerability. This issue could allow a remote and unauthenticated attacker to access sensitive information without authorization.

Solution

Upgrade to version 14.1-43.56, 13.1-58.32, 13.1-37.235-FIPS, 12.1-55.328-FIPS or later.

See Also

https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/r

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420c

Plugin Details

Severity: Critical

ID: 114907

Type: remote

Published: 7/10/2025

Updated: 7/10/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 7.1

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2025-5777

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CVSS Score Source: CVE-2025-5777

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

CVSS Score Source: CVE-2025-5777

Vulnerability Information

CPE: cpe:2.3:a:citrix:netscaler:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/8/2025

Reference Information

CVE: CVE-2025-5777