Improper access control in NetScaler Console (formerly NetScaler ADM) and NetScaler SDX (SVM) - CVE-2025-4365
Published: June 17, 2025
Vulnerability identifier: #VU111238
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4365
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to read arbitrary files on the system.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and read arbitrary files on the system.
Affected software
NetScaler Console (formerly NetScaler ADM)
NetScaler SDX (SVM)
NetScaler SDX (SVM)
How to mitigate CVE-2025-4365
Install updates from vendor's website.
NetScaler Console (formerly NetScaler ADM) - addressed in versions 13.1.58.32, 14.1.47.46
NetScaler SDX (SVM) - addressed in versions 13.1.58.32, 14.1.47.46
NetScaler SDX (SVM) - addressed in versions 13.1.58.32, 14.1.47.46