Impact
Citrix NetScaler ADC and Gateway are subject to a memory overflow vulnerability that can allow an unauthenticated attacker to execute arbitrary code or crash the system. The flaw arises from improper bounds checking during processing of incoming data, resulting in a buffer overflow that the attacker can exploit to take control of the device or cause a denial of service. This impacts confidentiality, integrity, and availability of the affected appliance.
Affected Systems
The vulnerability affects Citrix NetScaler ADC versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP. It also affects Citrix NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. All older releases listed in the Citrix advisory are susceptible.
Risk and Exploitability
With a CVSS score of 9.5 the flaw is considered Critical and can be abused remotely over the network. EPSS is not available, but the lack of exploit data does not reduce the severity; the KEV catalog lists it as not yet identified, meaning no known public exploits at the time of analysis. The attack vector is inferred to be remote over the untrusted network, requiring only network connectivity to the appliance. An attacker with sufficient privileges to send crafted input can gain full control or cause a crash.
OpenCVE Enrichment