Impact
The vulnerability is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, leading to a denial of service condition when an attacker can cause the affected components to crash or become unresponsive. The weakness involves improper handling of memory buffers and is categorized as a buffer overflow (CWE‑119).
Affected Systems
Affected vendors include Citrix NetScaler ADC and NetScaler Gateway. The ADC is vulnerable in versions prior to 14.1‑73.41, 13.1‑64.28, 14.1‑73.41 (FIPS), and 13.1‑37.282. The Gateway is vulnerable in versions before 14.1‑73.41 and before 13.1‑64.28.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, which suggests no public exploits are currently known. The attack vector is not explicitly stated; it is likely that an attacker would need to send crafted traffic or otherwise interact with the vulnerable component to trigger the memory overflow. The impact would be limited to crashing the affected ADC or Gateway, potentially disrupting network services for users of the Citrix environment.
OpenCVE Enrichment