CVE-2025-4365 is an arbitrary file read vulnerability affecting Citrix NetScaler Console and NetScaler SDX (SVM). This high-severity flaw, with a CVSS score of 7.5, allows an unauthenticated attacker to remotely access sensitive files without user interaction, leading to a high impact on confidentiality. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, its FAUCET Risk Score of 73/100 indicates a significant potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.1CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_console:13.1:build12.50:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_console:13.1:build17.42:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_console:13.1:build21.53:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_console:13.1:build24.38:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_console:13.1:build27.62:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.