Impact
Citrix NetScaler ADC and Gateway suffer a flaw that, when exploited, may allow an attacker remote privileged actions or significant unauthorized activities. The vulnerability spans multiple product releases from ADC versions 14.1 through 73.32 and from 13.1 through 63.21, as well as the same version ranges for Gateway. The description does not specify the precise mechanism; however, the CVSS score of 8.8 indicates high severity and the potential for significant compromise of the appliance or the network.
Affected Systems
The issue affects all Citrix NetScaler ADC and Gateway appliances within the specified version ranges, namely ADC 14.1‑73.32 and 13.1‑63.21, and Gateway 14.1‑73.32 and 13.1‑63.21. These versions are deployed in data centers worldwide and serve as load‑balancing or secure‑gateway devices.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity, indicating a significant potential impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity still demands prompt action. Based on the description, it is inferred that the attack vector is remote, likely through access to the appliance’s management interface, which would allow an adversary to send crafted traffic and gain elevated privileges or conduct unauthorized operations.
OpenCVE Enrichment