Impact
Multiple memory overflows exist in NetScaler ADC and NetScaler Gateway. These buffer overflows can result in unpredictable or erroneous behavior and ultimately cause a denial of service when the ADC operates as an Oracle load balancer, a DNS proxy, or a DNS recursive resolver. The primary impact is loss of availability for services that rely on the affected ADC instance. The vulnerability is a classic buffer overflow (CWE‑119). It is inferred that an attacker would need to target the ADC with specially crafted traffic to exploit the overflow.
Affected Systems
The affected products are Citrix NetScaler ADC and NetScaler Gateway. The advisory does not list specific firmware or software versions, so any deployment that places the ADC in one of the aforementioned configurations—Oracle load balancer, DNS proxy, or DNS recursive resolver—is potentially vulnerable. No other devices or versions were mentioned.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is not available, suggesting no publicly known exploitation data yet but high potential risk. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need network access to the NetScaler device and the ability to target it in the specific configurations. It is inferred that the attack vector is network‑based, requiring an adversary to send malformed or oversized packets to the ADC to trigger the overflow, which could crash the service and cause a denial of service.
OpenCVE Enrichment