CVE-2025-6543
Citrix · Published June 25, 2025
9.8
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Affected Products
- Netscaler Application Delivery Controller < 13.1-37.236
- Netscaler Application Delivery Controller < 13.1-59.19
- Netscaler Application Delivery Controller < 14.1-47.46
- Netscaler Gateway < 13.1-59.19
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H