CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- Affected products
- Citrix Netscaler Adc, Citrix Netscaler Gateway
- Citrix Netscaler Application Delivery Controller
- < 13.1-37.236, 13.1-59.19, 14.1-47.46
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 10.1% (95th percentile)
- Weakness
- CWE-119
- NVD status
- Analyzed
- Published
- 2025-06-25
CVE-2025-6543 at NVD
4 known exploits for CVE-2025-6543
Proof-of-concept code and exploit modules indexed by Sploitus
đź“„ NetScaler 14.1 Vulnerability Scanner
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Netscaler_Application_Delivery_Controller