CVE-2025-12101: Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12101?
CVE-2025-12101 is considered to have a high severity due to its potential to allow Cross-Site Scripting (XSS) attacks on vulnerable systems.
How do I fix CVE-2025-12101?
To fix CVE-2025-12101, update your Citrix NetScaler ADC or NetScaler Gateway to the latest version provided by Citrix that addresses this vulnerability.
Which products are affected by CVE-2025-12101?
CVE-2025-12101 affects Citrix NetScaler ADC and Citrix NetScaler Gateway when configured as a Gateway or AAA virtual server.
What are the potential impacts of CVE-2025-12101?
The potential impacts of CVE-2025-12101 include unauthorized access and data theft through XSS attacks.
Is there a workaround for CVE-2025-12101 if a patch cannot be applied immediately?
While an official workaround has not been specified, it is advisable to limit access to the affected components and review security configurations until the patch can be applied.