Impact
The CVE identifier refers to a vulnerability affecting the firmware of Citrix NetScaler ADC and Gateway appliances; however, the description does not reveal the precise weakness or exploitation technique. The associated CVSS score of 9.3 indicates a high severity assessment, but because the CVE data is silent about the actual impact, a definitive conclusion such as remote code execution is not stated and can only be presumed as a possibility based on the score.
Affected Systems
The flaw applies to NetScaler ADC versions from 14.1 through 73.32 and 13.1 through 63.21, and to NetScaler Gateway versions in the same ranges. Administrators should verify the firmware version running on their appliances against these ranges.
Risk and Exploitability
The high CVSS score signals a critical threat, and the EPSS score of 3% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no widely reported exploitation to date. The lack of an explicit attack vector in the description means the exact method of compromise is unknown; however, the devices’ typical exposure to external networks suggests that an attacker could potentially target the appliance if a suitable exploitation path is discovered. The vulnerability remains significant simply due to the severity rating and the broad version coverage.
OpenCVE Enrichment