Impact
Improper input validation in Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to construct malicious input that bypasses security checks and executes arbitrary commands on the underlying host. This flaw can lead to complete control of the appliance, enabling attackers to exfiltrate data, modify configurations, or pivot to other network resources. The vulnerability is classified as a Remote Code Execution flaw.
Affected Systems
Affected systems include Citrix NetScaler ADC versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP, as well as Citrix NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23. All firmware revisions listed are impacted and require update or mitigation.
Risk and Exploitability
The CVSS score of 9.5 signals a critical severity, and while the EPSS score is not available, the lack of a KEV listing does not reduce the risk. Based on the description, the flaw can be exploited remotely over the network by sending crafted requests to the appliance’s web interface, with no authentication required. The high severity and broad availability of the attack vector make timely remediation essential.
OpenCVE Enrichment