HIGH
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Published Aug 26, 2025
8.8
HIGHCVSS 4.0
EPSS 8.21%
Description
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it
Affected products
-
- Version 12.1 FIPS and NDcPPStatusaffectedConstraints<55.330
- Version 13.1StatusaffectedConstraints<59.22
- Version 13.1 FIPS and NDcPPStatusaffectedConstraints<37.241
- Version 14.1StatusaffectedConstraints<47.48
- Version
-
- Version 12.1 FIPS and NDcPPStatusaffectedConstraints<55.330
- Version 13.1StatusaffectedConstraints<59.22
- Version 13.1 FIPS and NDcPPStatusaffectedConstraints<37.241
- Version 14.1StatusaffectedConstraints<47.48
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| NetScaler | ADC | unaffected |
| |||||||||||||||
| NetScaler | Gateway | unaffected |
|
Configuration 1
OR
- ≥ 12.1 · < 12.1-55.330
- ≥ 12.1 · < 12.1-55.330
- ≥ 13.1 · < 13.1-37.241
- ≥ 13.1 · < 13.1-37.241
- ≥ 13.1 · < 13.1-59.22
- ≥ 14.1 · < 14.1-47.48
Configuration 2
OR
- ≥ 13.1 · < 13.1-59.22
- ≥ 14.1 · < 14.1-47.48
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25901 Advisory
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25901 | Advisory | |
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Citrix
Published Aug 26, 2025
Updated Aug 27, 2025
Reserved Jul 17, 2025
Link CVE-2025-7776
CISA Vulnrichment
Updated Aug 27, 2025
ENISA EUVD
EUVD-2025-25901 Assigner Citrix
Published Aug 26, 2025
Updated Aug 27, 2025
Exploited since n/a
Link EUVD-2025-25901