Impact
The vulnerability is a memory overflow in Citrix NetScaler ADC and Gateway that can cause unpredictable or erroneous behavior, including a denial of service. The flaw stems from improper validation of buffer boundaries, classified as CWE-119, and can allow an attacker to disrupt services without taking direct control of the device.
Affected Systems
Affected are Citrix NetScaler ADC versions earlier than 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS or NDcPP; and Citrix NetScaler Gateway versions earlier than 14.1-73.37 and 13.1-64.23.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers could exploit the memory overflow by sending crafted traffic to the affected NetScaler devices over the network, leading to service interruption. The lack of a public exploit or listed KEV status does not reduce the risk, as the high CVSS and common network entry surface suggest a realistic threat.
OpenCVE Enrichment