CVE-2025-6543: Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Other sources
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR as an AAA virtual server, since the vulnerability applies when configured as Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual server.
Citrix NetScaler ADC and Gateway Virtual server configuration (Gateway vs AAA) = Configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6543?
The severity of CVE-2025-6543 is classified as high due to its potential for denial of service.
How do I fix CVE-2025-6543?
To fix CVE-2025-6543, update your Citrix NetScaler ADC and NetScaler Gateway to the latest security patches provided by Citrix.
What systems are affected by CVE-2025-6543?
CVE-2025-6543 affects Citrix NetScaler ADC and Citrix NetScaler Gateway when configured as specific virtual servers.
What are the potential impacts of CVE-2025-6543?
The potential impacts of CVE-2025-6543 include unintended control flow and service disruption leading to denial of access.
Is there a workaround for CVE-2025-6543?
Citrix recommends implementing temporary security measures while awaiting the official patch for CVE-2025-6543.