Improper access control in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2025-5349

 

Improper access control in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2025-5349

Published: June 17, 2025


Vulnerability identifier: #VU111236
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5349
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in NetScaler Management Interface. A remote non-authenticated attacker with access to NSIP, Cluster Management IP or local GSLB Site IP can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

Citrix Netscaler ADC
Citrix NetScaler Gateway

How to mitigate CVE-2025-5349

Install updates from vendor's website.

Citrix Netscaler ADC - addressed in versions 12.1-55.328, 13.1-37.235, 13.1-58.32, 14.1-43.56
Citrix NetScaler Gateway - addressed in versions 13.1-58.32, 14.1-43.56

External References

Related Security Bulletins