Impact
Citrix NetScaler ADC and Gateway contain a flaw that undermines feature policy controls by incorrectly evaluating HTTP URL based expressions. The result is a bypass of intended policy restrictions, enabling an attacker to use functionality that would normally be blocked. The vulnerability does not explicitly state changes to confidentiality or integrity, but it compromises the integrity of the policy enforcement mechanism.
Affected Systems
The affected releases are Citrix NetScaler ADC versions before 14.1‑73.37, before 13.1‑64.23, and the corresponding FIPS and NDcPP builds, as well as Citrix NetScaler Gateway versions prior to 14.1‑73.37 and 13.1‑64.23. All these releases are vulnerable to the feature policy bypass.
Risk and Exploitability
The CVSS score of 7.0 indicates high severity, but the EPSS score is not available, so the likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog. An attacker could trigger the flaw by sending specially crafted HTTP requests that exploit the improper handling of URL based expressions. The attack vector is inferred from the description since explicit details are not provided.
OpenCVE Enrichment