Impact
The CVE designates a high‑severity flaw in Citrix NetScaler ADC and NetScaler Gateway firmware that involves improper buffer handling (CWE-120). The description does not disclose the precise mechanism or exploitation conditions, but the CVSS score of 8.8 signals a significant potential impact if the flaw is leveraged. The EPSS score of 0.00345 indicates a low exploitation probability, and the issue is not listed in the CISA KEV catalog, indicating that the likelihood of exploitation is unknown but the severity warrants rapid attention.
Affected Systems
Advisory covers Citrix NetScaler ADC firmware ranges from version 14.1 through 73.32 and from 13.1 through 63.21, and NetScaler Gateway firmware ranges from 14.1 through 73.32 and from 13.1 through 63.21.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is classified as high severity and could enable significant adverse effects on confidentiality, integrity, or availability if exploited. Because the description does not specify an attack vector, it remains uncertain whether flaw is remote or local. The EPSS score of 0.00345 indicates a low estimated exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the high severity indicates that the flaw should be treated with priority.
OpenCVE Enrichment