- Description
- Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
- Source
- secure@citrix.com
- NVD status
- Analyzed
- Products
- netscaler_application_delivery_controller, netscaler_gateway
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@citrix.com
- CWE-1284
- nvd@nist.gov
- NVD-CWE-Other
- Hype score
- Not currently trending
Citrix Bleed 2.0 (CVE-2025-5777 & CVE-2025-5349) Citrix has disclosed two critical vulnerabilities affecting NetScaler ADC and Gateway. Patch immediately to fixed builds as listed in CTX693420. https://t.co/E9MwaWRzQ3 https://t.co/4ymn1iIQtV
@CyberTitanLLC
31 Jul 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
There is an update to Citrix Bleed 2 - CVE-2025-5349 and CVE-2025-5777 . Apparently, only one article is referenced to test for possible compromise. https://t.co/dDLO4CFnoS Dear admin colleagues, how many are currently rotating and looking for patches?
@NickInformation
25 Jul 2025
438 Impressions
3 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-5349 and CVE-2025-5777 Article Id : CTX693420 Last Modified Date : 07-25-2025 17:33 Created Date : 06-17-2025 11:48 https://t.co/Zh1McSSDCO
@endi24
25 Jul 2025
264 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Nuevas vulnerabilidades críticas en Citrix Las vulnerabilidades, identificadas como CVE-2025-5349 y CVE-2025-5777, afectan a múltiples versiones de Citrix NetScaler. Más información: https://t.co/XtXEQOe1Rl #Citrix #vulnerability https://t.co/U4oFQqsoLP
@CSIRT_Telconet
19 Jul 2025
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Vulnerabilidades en los productos Citrix NetScaler ❗CVE-2025-5777 ❗CVE-2025-5349 ➡️Más info: https://t.co/2quJ6vQiIW https://t.co/Rp1SGTPb2H
@CERTpy
8 Jul 2025
152 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 #CitrixBleed 2.0? We break down CVE-2025-5777, CVE-2025-5349, and CVE-2025-6543 — what’s known, what’s not, and why admin creds may be at risk. If you run #NetScaler, read this now 👇 https://t.co/wgpafxDLsj #infosec #cybersecurity https://t.co/IX5cRcBZ5K
@Horizon3ai
7 Jul 2025
546 Impressions
10 Retweets
10 Likes
3 Bookmarks
2 Replies
0 Quotes
Critical vulnerabilities CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543 in Citrix NetScaler ADC & Gateway are exploited in the wild, risking unauthorized access & credential leaks. Update now! ⚠️ #NetScaler #CyberAlert #USA https://t.co/m6qSFeBhx9
@TweetThreatNews
6 Jul 2025
86 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Warning: Two Critical vulnerabilities in @Citrix #ISE. CVE-2025-5777 (CVSS 9.3) and CVE-2025-5349 (CVSS 9.2) allow unauthenticated remote memory overread and #DoS. Both are #ActivelyExploited! Immediate action required to secure your systems. #Patch https://t.co/HoZhS9HZHn
@CCBalert
30 Jun 2025
365 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-5349
@transilienceai
29 Jun 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2025-5349
@transilienceai
29 Jun 2025
21 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
#CyberAlert | Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway We are aware of the security advisories published by Citrix for critical vulnerabilities, CVE-2025-5349, CVE-2025-5777 and CVE-2025-6543. https://t.co/FHQLsyNzqT 🧵
@cybercentre_ca
26 Jun 2025
142 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
La faille CVE-2025-5349 cible NetScaler Citrix et est déjà exploitée. Citrix recommande de fermer toutes les sessions actives après correctif. @ValeryMarchive #cybersécurité 👉 https://t.co/4s9M7sMeL1 https://t.co/ZcHZzxJRw4
@LeMagIT
26 Jun 2025
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Security Bulletin: Multiple vulnerabilities affecting Citrix NetScaler – CVE-2025-5777 & CVE-2025-5349 allow memory leaks and unauthorized admin access. Patch to 14.1-43.56 or later + restrict interface access to reduce risk. #ThreatIntel #Re... https://t.co/MYPMybTdj8
@RedLegg
25 Jun 2025
42 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
【CitrixがNetScalerの重大バグCVE-2025-5777を修正】この境界外読み取りの脆弱性が悪用された形跡はないが、なるべく早くパッチを適用し、アクティブなセッションを終了するよう推奨されている。CVE-2025-5349(不適
@MachinaRecord
24 Jun 2025
106 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨Upozorňujeme na kritické zranitelnosti v load balanceru NetScaler ADC, CVE-2025-5349 a v bráně pro vzdálený přístup NetScaler Gateway, CVE-2025-5777. První zranitelnost spočívá v nesprávném řízení přístupu v rozhraní pro správu NetScaler ADC a druhá v c
@GOVCERT_CZ
19 Jun 2025
54 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Two critical vulnerabilities, CVE-2025-5349 (8.7) and CVE-2025-5777 (9.3), found in NetScaler ADC & Gateway. Outdated versions are at risk of unauthorized access & memory overreads. Ensure updates are applied swiftly! ⚠️ #NetScaler #CyberRisk https://t.co/cQgYw6ulAJ
@TweetThreatNews
19 Jun 2025
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical vulnerability in NetScaler ADC and NetScaler Gateway URL: https://t.co/4gu12PtexF Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.3 CVEs: CVE-2025-5777, CVE-2025-5349
@samilaiho
18 Jun 2025
111 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical vulnerabilities (CVE-2025-5349, CVE-2025-5777) have been identified in NetScaler ADC and NetScaler Gateway. Immediate customer action is strongly advised. Read the full security bulletin here: https://t.co/Il5TcAyDue https://t.co/vgBFfzaYVh
@FerroqueSystems
17 Jun 2025
231 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent alert! #Citrix Netscaler ADC, -SDX, and -Console are now affected by new security vulnerabilities identified as CVE-2025-4365, CVE-2025-5349, and CVE-2025-5777. Check out https://t.co/iNgUoraIAC and https://t.co/xQhkxrNkvK
@Koetzing
17 Jun 2025
806 Impressions
5 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
New @Citrix article: #NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-5349 and CVE-2025-5777 https://t.co/uV5eDdaL7c
@guyrleech
17 Jun 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-5349 Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway https://t.co/2uFROryU52
@CVEnew
17 Jun 2025
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"matchCriteriaId": "D907BEC2-6930-4989-A6E1-847B4763BB12",
"versionEndExcluding": "12.1-55.328",
"versionStartIncluding": "12.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"matchCriteriaId": "7AF5A6EE-84A9-42AA-BC4B-7C3367D08CAF",
"versionEndExcluding": "13.1-37.235",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
"matchCriteriaId": "E219F46B-FCBE-4DA2-9094-6ED128E8AF66",
"versionEndExcluding": "13.1-37.235",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"matchCriteriaId": "48A64F62-2A5A-40CB-A507-A48497BD749A",
"versionEndExcluding": "13.1-58.32",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"matchCriteriaId": "6484AA47-81F8-4EE6-9F33-96DEFE2F66E1",
"versionEndExcluding": "14.1-43.56",
"versionStartIncluding": "14.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2C86D66F-888F-4519-B700-9ADC4EE6913C",
"versionEndExcluding": "13.1-58.32",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D4E61FAA-9EAB-4F9B-887F-C5DC0DA0C633",
"versionEndExcluding": "14.1-43.56",
"versionStartIncluding": "14.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]