Essential Vulnerabilities in NetScaler ADC & Gateway – CVE-2025-5349

Published:

Cloud Software Group Issues Security Advisory for Vulnerabilities in NetScaler Products

Cloud Software Group has recently issued a significant security bulletin concerning two newly discovered vulnerabilities, CVE-2025-5349 and CVE-2025-5777. These issues affect both NetScaler ADC (formerly known as Citrix ADC) and NetScaler Gateway (previously Citrix Gateway), posing a serious risk to users of these software products.

Overview of the Vulnerabilities

CVE-2025-5349: Improper Access Control

The first vulnerability, CVE-2025-5349, has been identified as an improper access control issue impacting the NetScaler Management Interface. If exploited, this flaw could allow unauthorized users to gain elevated access simply by connecting through the Network Services IP (NSIP), Cluster Management IP, or local GSLB Site IP. This vulnerability has been classified under the Common Weakness Enumeration (CWE) as CWE-284 and carries a high severity rating, with a CVSS v4.0 base score of 8.7.

CVE-2025-5777: Insufficient Input Validation

The second vulnerability, CVE-2025-5777, arises from insufficient input validation, leading to a memory overread condition. This vulnerability can only be exploited when the NetScaler is configured as a Gateway—that includes VPN virtual servers, ICA Proxy, CVPN, RDP Proxy, or AAA virtual servers. It falls under CWE-125, known as Out-of-bounds Read, and is considered even more critical, with a CVSS v4.0 base score of 9.3.

Affected Versions of NetScaler Software

Cloud Software Group has released a list of affected versions for both NetScaler ADC and NetScaler Gateway:

  • NetScaler ADC and NetScaler Gateway Version 14.1 prior to 14.1-43.56
  • NetScaler ADC and NetScaler Gateway Version 13.1 prior to 13.1-58.32
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before build 13.1-37.235-FIPS and NDcPP
  • NetScaler ADC 12.1-FIPS before build 12.1-55.328-FIPS

It’s essential for users to note that versions 12.1 and 13.0 have reached their End of Life (EOL), meaning they are no longer supported. These versions remain vulnerable to both CVE-2025-5349 and CVE-2025-5777. Users running these outdated builds are strongly encouraged to upgrade to supported versions immediately.

Furthermore, organizations utilizing Secure Private Access in on-premises or hybrid deployments must also update their NetScaler instances to the specified secure builds for protection against these vulnerabilities.

Recommended Actions for Remediation

To effectively address these vulnerabilities, Cloud Software Group recommends that customers upgrade to the following versions:

  • NetScaler ADC and NetScaler Gateway 14.1-43.56 or later
  • NetScaler ADC and NetScaler Gateway 13.1-58.32 or later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.235 or later
  • NetScaler ADC 12.1-FIPS 12.1-55.328 or later

After performing the upgrade, administrators should terminate all active ICA and PCoIP sessions with the following commands to mitigate lingering vulnerabilities:

bash
kill icaconnection -all
kill pcoipConnection -all

These commands should only be executed after confirming that all appliances within an HA pair or cluster have been fully updated to secure builds.

It’s important to mention that these vulnerabilities specifically impact customer-managed instances of Citrix ADC and Citrix Gateway. Organizations using Citrix-managed cloud services or Citrix Adaptive Authentication are not required to take any action, as Cloud Software Group manages all necessary updates in those environments.

Acknowledgments and Industry Collaboration

In this advisory, Cloud Software Group extends its gratitude to Positive Technologies and ITA MOD CERT (CERTDIFESA) for their collaborative efforts in responsibly identifying and disclosing these vulnerabilities. Such cooperation has been essential in facilitating a timely and effective response to safeguard end-users.

Given the severity of CVE-2025-5349 and CVE-2025-5777, organizations that rely on NetScaler ADC and NetScaler Gateway must prioritize their updates. With one vulnerability permitting elevated access and the other enabling potential memory exploits, the risk of unauthorized control over affected systems is significant. Upgrading to the latest supported versions is not just advisable but crucial for maintaining a secure infrastructure.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...

US DHS allegedly compiles protester dossiers in Palantir database, court filing reveals

Newly unsealed court documents allege that the US Department of Homeland Security (DHS) has compiled extensive dossiers on individuals observing Immigration and Customs Enforcement...