{"id":"CVE-2025-5777","title":"Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server","summary":"Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-125","CWE-908","CWE-457"],"vendor":"citrix","product":"netscaler_application_delivery_controller","affected":["netscaler_application_delivery_controller >= 12.1, < 12.1-55.328","netscaler_application_delivery_controller >= 13.1, < 13.1-37.235","netscaler_application_delivery_controller >= 13.1, < 13.1-58.32","netscaler_application_delivery_controller >= 14.1, < 14.1-43.56","netscaler_gateway >= 13.1, < 13.1-58.32","netscaler_gateway >= 14.1, < 14.1-43.56"],"patched":["netscaler_application_delivery_controller 14.1-43.56","netscaler_gateway 14.1-43.56"],"published":"2025-06-17","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-5777","references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420","label":"secure@citrix.com"},{"url":"https://citrixbleed.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99972,"epssPercentile":0.99977,"kev":true,"kevDateAdded":"2025-07-10","kevDueDate":"2025-07-11","kevRansomware":true,"exploited":true,"exploitAvailable":true,"ingestedAt":"2026-08-04T05:36:13.009Z","exploits":{"exploitdb":true,"github":26,"githubRepos":["https://github.com/mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-","https://github.com/RickGeex/CVE-2025-5777-CitrixBleed","https://github.com/idobarel/CVE-2025-5777"],"nuclei":["CVE-2025-5777"],"checkedAt":"2026-09-19T16:22:59.353Z"},"slug":"CVE-2025-5777","body":"## Overview\n\nInsufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server\n\n## Affected\n\n- `netscaler_application_delivery_controller >= 12.1, < 12.1-55.328`\n- `netscaler_application_delivery_controller >= 13.1, < 13.1-37.235`\n- `netscaler_application_delivery_controller >= 13.1, < 13.1-58.32`\n- `netscaler_application_delivery_controller >= 14.1, < 14.1-43.56`\n- `netscaler_gateway >= 13.1, < 13.1-58.32`\n- `netscaler_gateway >= 14.1, < 14.1-43.56`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `netscaler_application_delivery_controller 14.1-43.56`\n- `netscaler_gateway 14.1-43.56`","depth":"abyssal","depthScore":91,"depthScoreParts":{"impact":41.3,"likelihood":20,"exploitation":25,"ransomware":5},"changes":[]}