CVE-2025-5777
HIGH CISA KEVDescription
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| citrix | netscaler_application_delivery_controller |
| citrix | netscaler_application_delivery_controller |
| citrix | netscaler_application_delivery_controller |
| citrix | netscaler_application_delivery_controller |
| citrix | netscaler_application_delivery_controller |
| citrix | netscaler_gateway |
| citrix | netscaler_gateway |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-5777? +
How severe is CVE-2025-5777? +
What products are affected by CVE-2025-5777? +
How do I check if I'm vulnerable to CVE-2025-5777? +
Related Vulnerabilities
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() …
An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system …
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read …
Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to …
An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation …
Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects NotepadNext: …