Impact
A malformed HTTP/2 request can trigger a denial-of-service condition in Citrix NetScaler ADC and NetScaler Gateway appliances when HTTP/2 is enabled in an HTTP Profile linked to a virtual server or service. The flaw causes the device to consume excessive resources and become unresponsive to legitimate traffic, effectively taking the managed services offline. This is a classic memory exhaustion or resource depletion weakness (CWE‑401).
Affected Systems
Citrix NetScaler ADC and NetScaler Gateway appliances that have HTTP/2 enabled in an HTTP Profile associated with a virtual server of type Load Balancing, Content Switching, or VPN, or with a service configured on NetScaler. No specific vendor version is listed, so the issue applies to all affected product editions that permit the configuration in question.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score is not available, so the exploitation probability cannot be quantified. The flaw is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The likely attack vector is remote, where an adversary sends specially crafted HTTP/2 traffic to the exposed NetScaler interfaces. Successful exploitation would result in denial of service for legitimate users and potentially disrupt business availability.
OpenCVE Enrichment