CVE-2025-5777 is a critical memory overread vulnerability affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway when configured as a Gateway or AAA virtual server. This flaw, stemming from insufficient input validation, allows for sensitive information disclosure. With a CVSS score of 7.5 (HIGH) and an EPSS percentile of 0.698150000, it poses a significant risk due to its network-based attack vector, low attack complexity, and high confidentiality impact. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, and public exploit code (CitrixBleed 2, EDB-52401) and extensive community discussion (69 mentions) confirm its widespread attention and immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-55.328CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 13.1, < 13.1-37.235CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 13.1, < 13.1-37.235CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* | ||
>= 13.1, < 13.1-58.32CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* | ||
>= 14.1, < 14.1-43.56CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.