CVE-2025-5349: NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interface
Published Jun 17, 2025
·Updated
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
Affected Software
9 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Citrix NetScaler Application Delivery Controller>=12.1<12.1-55.328
Citrix NetScaler Application Delivery Controller>=13.1<13.1-37.235
Citrix NetScaler Application Delivery Controller>=13.1<13.1-37.235
Citrix NetScaler Application Delivery Controller>=13.1<13.1-58.32
Citrix NetScaler Application Delivery Controller>=14.1<14.1-43.56
Citrix NetScaler Gateway>=13.1<13.1-58.32
Citrix NetScaler Gateway>=14.1<14.1-43.56
Event History
Feb 19, 2024
News Published
via The Register·01:29 AM
Mar 11, 2024
News Published
via The Register·04:28 AM
Jun 17, 2024
News Published
via The Register·01:59 AM
Nov 25, 2024
News Published
via The Register·01:30 AM
Feb 17, 2025
News Published
via The Register·02:25 AM
Mar 16, 2025
News Published
via The Register·10:58 PM
Mar 30, 2025
News Published
via The Register·10:45 PM
Jun 17, 2025
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 23, 2025
News Published
via The Register·12:33 AM
Jun 25, 2025
News Published
via BleepingComputer·04:10 PM
News Published
via BleepingComputer·04:12 PM
Feb 8, 2026
News Published
via The Register·10:25 PM
News Published
via The Register·10:28 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5349?
CVE-2025-5349 has a high severity rating due to improper access control vulnerabilities that could allow unauthorized access.
2
How do I fix CVE-2025-5349?
To mitigate CVE-2025-5349, apply the latest security updates and patches provided by Citrix for the affected products.
3
What are the potential risks associated with CVE-2025-5349?
The risks include unauthorized access to the NetScaler Management Interface, potentially leading to data breaches or system compromises.
4
Which products are affected by CVE-2025-5349?
CVE-2025-5349 affects Citrix NetScaler ADC and Citrix NetScaler Gateway.
5
How can I determine if my system is vulnerable to CVE-2025-5349?
You can determine vulnerability to CVE-2025-5349 by checking if you are using an affected version of Citrix NetScaler ADC or Gateway and if security patches are applied.