GPU VulnDB

Database/Control plane, storage & DevOps

Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server): A memory

CVE-2025-6543Control plane, storage & DevOpsKnown exploitedCTX694788curated

Impact

A memory overflow in the Gateway/AAA code path corrupts control flow, letting an attacker crash the appliance (denial of service) and, per CISA's KEV listing, this has been exploited in the wild — meaning it's already a live threat to any NetScaler used as the VPN entry point into a cluster's management network.

Who can reach it

Remote, targeting a NetScaler configured as a Gateway/AAA virtual server (i.e. the VPN/ICA-proxy entry point) — exact prerequisites are undisclosed by Citrix, consistent with an actively-exploited memory-corruption bug.

What to do

Software upgrade to the fixed NetScaler ADC/Gateway build per Citrix advisory CTX694788, then reboot. Given confirmed in-the-wild exploitation, patch ahead of the normal cycle — this is the box guarding VPN access into the cluster's OOB/management network, not just a data-plane load balancer.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.