« Back to list

CVE-2025-8424

Status: DeferredHigh (8.7)—

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-8424",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-8424",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-27T03:55:15.625808Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "secure@citrix.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "LOW",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "LOW",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "secure@citrix.com",
      "affectedData": [
        {
          "vendor": "NetScaler",
          "product": "ADC",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "47.48",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1",
              "lessThan": "59.22",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1 FIPS and NDcPP",
              "lessThan": "37.241",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "12.1 FIPS and NDcPP",
              "lessThan": "55.330",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NetScaler",
          "product": "Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "47.48",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1",
              "lessThan": "59.22",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1 FIPS and NDcPP",
              "lessThan": "37.241",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "12.1 FIPS and NDcPP",
              "lessThan": "55.330",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-26T14:15:44.740",
  "references": [
    {
      "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938",
      "source": "secure@citrix.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@citrix.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access"
    },
    {
      "lang": "es",
      "value": "Control de acceso inadecuado en la interfaz de administración de NetScaler en NetScaler ADC y NetScaler Gateway cuando un atacante puede obtener acceso a la NSIP del dispositivo, la IP de administración del clúster o la IP del sitio GSLB local o SNIP con acceso de administración"
    }
  ],
  "lastModified": "2026-06-17T10:06:57.597",
  "sourceIdentifier": "secure@citrix.com"
}