Full Report
Citrix is warning that a vulnerability in NetScaler appliances tracked as CVE-2025-6543 is being actively exploited in the wild, causing devices to enter a denial of service condition. [...]
Analysis Summary
# Vulnerability: Citrix NetScaler Denial of Service Vulnerability
## CVE Details
- CVE ID: [Not explicitly detailed for the DoS in the provided text, but linked to an active exploitation]
- CVSS Score: [Not explicitly detailed, but referred to as a critical bug]
- CWE: [Undetermined, linked to Denial of Service]
*(Note: The text mentions CVE-2025-5777 for a second, different vulnerability (session hijacking, named CitrixBleed 2). This summary focuses on the primary vulnerability discussed: the DoS flaw that is reportedly being exploited.)*
## Affected Systems
- Products: Citrix NetScaler ADC and NetScaler Gateway
- Versions: Information on specific vulnerable versions for the DoS flaw is not explicitly listed in patch notes segment; however, customers are advised to update to versions listed below.
- Configurations: Vulnerable when configured as a Gateway (VPN virtual server, ICA Proxy, Clientless VPN (CVPN), RDP Proxy) or an Authentication, Authorization, and Accounting (AAA) virtual server.
## Vulnerability Description
The vulnerability in Citrix NetScaler products is being exploited in Denial of Service (DoS) attacks. The technical details of the DoS flaw are not specified beyond its effect.
## Exploitation
- Status: **Exploited in the wild** (Explicitly stated as being "exploited in DoS attacks")
- Complexity: [Not specified]
- Attack Vector: Likely **Network** due to the appliance's service role.
## Impact
- Confidentiality: [Unknown/Not Specified]
- Integrity: [Unknown/Not Specified]
- Availability: **High** (Due to successful Denial of Service exploitation)
## Remediation
### Patches
Citrix has issued patches for the affected product lines:
- NetScaler ADC and Gateway **14.1-47.46** and later releases.
- NetScaler ADC and Gateway **13.1-59.19** and later releases.
- ADC **13.1-FIPS** releases starting from **13.1-37.236** and later.
- NDcPP releases starting from **13.1-37.236** and later.
### Workarounds
- Administrators should **monitor their NetScaler instances for unusual user sessions and abnormal behavior.**
- Review access controls.
## Detection
- Indicators of compromise: Unusual user sessions, abnormal behavior indicating service disruption.
- Detection methods and tools: Monitoring NetScaler activity for potential DoS patterns.
## References
- Vendor advising application of latest patches from Citrix.
- Mention of a related, critical flaw: CVE-2025-5777 (CitrixBleed 2).
- General link: bleepingcomputer dot com / news / security / citrix-warns-of-netscaler-vulnerability-exploited-in-dos-attacks/