Impact
The reported vulnerability affects NetScaler ADC and Gateway firmware. The CVSS score of 9.3 indicates a critical severity. The weakness is characterized by authentication bypass, as denoted by CWE-288, which means an attacker may obtain unauthorized access to the appliance or its management interface. The vulnerability’s exact exploitation technique is not detailed, but it potentially allows operational control of the device.
Affected Systems
The flaw applies to NetScaler ADC versions from 14.1 through 73.32 and from 13.1 through 63.21, and to NetScaler Gateway versions in the same range. Administrators should check the firmware version of their appliances against these ranges.
Risk and Exploitability
The high CVSS score and EPSS score of 7% place this vulnerability in the high‑risk category. It is listed in CISA’s KEV catalog, indicating that it has already been exploited in the wild. While the description does not specify the attack vector, the CWE suggests that an attacker can bypass authentication and potentially gain full control of the appliance. Because the appliance is normally exposed to external networks, access to the vulnerable component is likely reachable, making the exploit feasible; this is inferred from typical deployment scenarios. The risk is compounded by the wide version coverage.
OpenCVE Enrichment