Impact
Citrix NetScaler ADC and Gateway suffer an HTTP Request/Response smuggling flaw caused by inconsistent interpretation of HTTP request headers, as identified by CWE-444. This weakness enables an attacker to craft malformed HTTP requests that are parsed differently by the load balancer and backend servers. As a result, the attacker can bypass security controls, inject malicious requests, or potentially execute arbitrary code or elevate privileges on the affected systems. The high CVSS score of 9.3 signals a severe potential impact on confidentiality, integrity, and availability.
Affected Systems
The vulnerability is present in Citrix NetScaler ADC versions prior to 14.1‑73.37, 13.1‑64.23, FIPS 14.1‑73.37, 13.1‑37.279, and NDcPP, as well as in Citrix NetScaler Gateway versions before 14.1‑73.37 FIPS and 13.1‑64.23. These affected releases feature buggy HTTP request processing that allows smuggling.
Risk and Exploitability
With a CVSS score of 9.3, the flaw poses a critical risk, but the EPSS score is not available, making the exact likelihood of exploitation unclear. The vulnerability is not listed in CISA KEV, suggesting no publicly known exploits yet. However, the attack vector is likely remote, requiring only that an attacker can send crafted HTTP requests through the load balancer to the backend. The inconsistency in header handling provides a straightforward exploitation path for advanced adversaries.
OpenCVE Enrichment