Description
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Published: 2026-06-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient input validation allows a memory overread when NetScaler ADC or NetScaler Gateway processes packets that contain an enabled TCP TimeStamp flag in a TCP Profile attached to a virtual server or service. The overread may expose internal memory contents, which could reveal sensitive configuration or credential information. This behavior aligns with CWE‑125, a classic memory overread that can lead to information disclosure.

Affected Systems

All NetScaler ADC and NetScaler Gateway instances in which the TCP TimeStamp feature is enabled in the TCP Profile and that profile is associated with a virtual server of type LB, CS, or VPN, or with a service. The advisory does not specify affected firmware versions, so the issue is assumed to apply to all current releases available before the cited update.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need remote network access and the ability to send traffic that activates the TCP TimeStamp in the target virtual server or service. The description does not confirm any code execution capability; the risk is limited to a potential memory overread that could disclose data.

Generated by OpenCVE AI on June 30, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the fix or update described in Citrix support article CTX696604.
  • Disable the TCP TimeStamp flag in the TCP Profile for all virtual servers and services that use it.
  • Verify that no legacy services or virtual servers still reference the TCP TimeStamp feature and monitor for related errors.

Generated by OpenCVE AI on June 30, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Title Insufficient input validation leading to memory overread
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-06-30T13:28:19.305Z

Reserved: 2026-06-04T05:49:25.173Z

Link: CVE-2026-10817

cve-icon Vulnrichment

Updated: 2026-06-30T13:28:11.612Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T18:45:15Z

Weaknesses