Memory Overflow Vulnerability Affecting NetScaler ADC and NetScaler Gateway by Citrix
CVE-2025-7775

9.2CRITICAL

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
26 August 2025

What is CVE-2025-7775?

A memory overflow vulnerability has been identified in Citrix's NetScaler ADC and NetScaler Gateway. This issue can lead to remote code execution or denial of service when the NetScaler is configured as a Gateway for VPN virtual servers, ICA Proxy, CVPN, RDP Proxy, or AAA virtual servers. The vulnerability specifically affects load balancing virtual servers using HTTP, SSL, or HTTP_QUIC that are bound to services or service groups utilizing IPv6. Users of versions 13.1, 14.1, 13.1-FIPS, and NDcPP should assess their configurations to mitigate potential impacts.

Affected Version(s)

ADC 14.1 < 47.48

ADC 13.1 < 59.22

ADC 13.1 FIPS and NDcPP < 37.241

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7775 : Memory Overflow Vulnerability Affecting NetScaler ADC and NetScaler Gateway by Citrix