Arbitrary File Read in Citrix NetScaler Console and SDX
CVE-2025-4365

6.9MEDIUM

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
17 June 2025

What is CVE-2025-4365?

An arbitrary file read vulnerability exists in Citrix NetScaler Console and NetScaler SDX, which may allow an unauthenticated attacker to access sensitive files on the affected system. This can lead to unauthorized exposure of data, potentially compromising the integrity and confidentiality of sensitive information. Users are advised to apply the appropriate security measures and patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Console 14.1 < 47.46

Console 13.1 < 58.32

SDX (SVM) 14.1 < 47.46

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4365 : Arbitrary File Read in Citrix NetScaler Console and SDX