Vulnerability record · CVE-2025-6543 · published 25 June 2025
CVE-2025-6543: Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoS
Citrix · Netscaler Application Delivery Controller
NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, so internet-facing remote access deployments are the exposed ones. The flaw is remotely reachable without authentication, and CISA added it to the Known Exploited Vulnerabilities catalog, making it a priority for edge-device patching.
Description
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityRemote unauthenticated memory corruption in internet-facing Citrix remote access appliances that is listed in CISA KEV with confirmed exploitation.
What it is
NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, so internet-facing remote access deployments are the exposed ones. The flaw is remotely reachable without authentication, and CISA added it to the Known Exploited Vulnerabilities catalog, making it a priority for edge-device patching.
Impact
An unauthenticated remote attacker can corrupt memory to redirect control flow and crash the appliance, disrupting VPN, ICA, RDP and AAA services. The CVSS 4.0 vector rates high confidentiality, integrity and availability impact, so code execution or data exposure beyond the DoS cannot be ruled out from the record.
Attack surface
Reached over the network via the Gateway or AAA virtual server on NetScaler ADC or Gateway; the CVSS vector shows no privileges required and no user interaction. Only appliances configured in those roles are affected, so exposure depends on the deployed configuration.
Exploitation
CVE-2025-6543 is listed in CISA KEV with a 2025-07-21 remediation due date, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 10.1 percent (95th percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor fix from Citrix advisory CTX694788 to all NetScaler ADC and Gateway appliances, prioritizing Gateway and AAA virtual server configurations.
- If patching cannot be done immediately, follow Citrix mitigation guidance or take the affected Gateway/AAA virtual server out of service per CISA BOD 22-01.
- Restrict management and virtual server access to trusted networks and disable unused Gateway or AAA virtual servers.
- Monitor Citrix and CISA advisories for updated guidance and verify patch level after upgrading.
Detection
- Review NetScaler logs for unexpected appliance restarts, crashes or process failures on Gateway and AAA virtual servers.
- Alert on anomalous or malformed traffic to VPN, ICA Proxy, CVPN, RDP Proxy and AAA virtual server endpoints.
- Audit NetScaler build versions against the fixed release in CTX694788 and flag unpatched appliances.
- Correlate NetScaler availability gaps with upstream network telemetry to catch denial-of-service attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-6543 to the Known Exploited Vulnerabilities catalog on 30 June 2025 as "Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 21 July 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6543 | US Government Resource |
Track CVE-2025-6543 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-6543), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.