CVE-2025-5777

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

History

21 Oct 2025, 23:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777 -

21 Oct 2025, 20:20

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:21

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777 -

14 Aug 2025, 14:52

Type Values Removed Values Added
References () https://citrixbleed.com - () https://citrixbleed.com - Third Party Advisory

13 Aug 2025, 19:15

Type Values Removed Values Added
References
  • () https://citrixbleed.com -

14 Jul 2025, 21:09

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 13:15

Updated : 2025-10-21 23:17


NVD link : CVE-2025-5777

Mitre link : CVE-2025-5777

CVE.ORG link : CVE-2025-5777


JSON object : View

Products Affected

citrix

  • netscaler_application_delivery_controller
  • netscaler_gateway
CWE
CWE-125

Out-of-bounds Read

CWE-908

Use of Uninitialized Resource

CWE-457

Use of Uninitialized Variable