CVE-2025-6543 is a critical memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway when configured as a Gateway or AAA virtual server, leading to unintended control flow and Denial of Service. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild and has garnered significant community discussion and media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB. Its inclusion in the KEV catalog and high FAUCET Risk Score underscore the urgent need for remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.1, < 13.1-37.236CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 13.1, < 13.1-37.236CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* | ||
>= 13.1, < 13.1-59.19CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* | ||
>= 14.1, < 14.1-47.46CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* | ||
>= 13.1, < 13.1-59.19CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.