CVE 9.2 CRITICAL

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service_CVE-2025-7775

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Description

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

(OR)

NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers

(OR)

NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers

(OR)

CR virtual server with type HDX

Basic Information

ID CVE-2025-7775
Source Citrix
Published Aug 26, 2025 at 12:56

Affected Product

Vendor NetScaler
Product ADC
Version 14.1
Affected Versions NetScaler ADC 14.1
NetScaler ADC 13.1
NetScaler ADC 13.1 FIPS and NDcPP
NetScaler ADC 12.1 FIPS and NDcPP
NetScaler Gateway 14.1
NetScaler Gateway 13.1
NetScaler Gateway 13.1 FIPS and NDcPP
NetScaler Gateway 12.1 FIPS and NDcPP

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.