/Vulnerability Library

Citrix NetScaler Memory Disclosure - CitrixBleed 2

CVE-2025-5777
Verified

Description

Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADC and NetScaler Gateway

Severity

Critical

CVSS Score

7.5

Exploit Probability

100%

Published Date

July 5, 2025

Template Author

watchtowr, dhiyaneshdk, darses

CVE-2025-5777.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-5777
CWE ID:
cwe-457

References

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/https://nvd.nist.gov/vuln/detail/CVE-2025-5777

Remediation Steps

Apply the security patches as described in Citrix support article CTX693420 and restrict access to the NetScaler Management Interface.