CVE-2025-8424:
Citrix ADC VPX Análisis y mitigación de vulnerabilidades
Vista general
CVE-2025-8424 is an improper access control vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. The vulnerability was disclosed on August 26, 2025, as part of a security advisory that included three vulnerabilities. This vulnerability received a CVSSv4 score of 8.7 (High) (Hacker News).
Técnicas
The vulnerability stems from improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway. While no privileges are required to exploit this vulnerability, an attacker would need access to the appliance NSIP, Cluster Management IP, local GSLB Site IP, or SNIP with Management Access (Tenable).
Impacto
The vulnerability could allow unauthorized access to management functions when an attacker can gain access to specific management interfaces of the appliance (NVD).
Mitigación y soluciones alternativas
Citrix has released patches to address this vulnerability in the following versions: NetScaler ADC and NetScaler Gateway 14.1-47.48 and later releases, NetScaler ADC and NetScaler Gateway 13.1-59.22 and later releases of 13.1, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.241 and later releases, and NetScaler ADC 12.1-FIPS and 12.1-NDcPP 12.1-55.330 and later releases (Rapid7).
Recursos adicionales
Fuente: Este informe se generó utilizando IA
Relacionado Citrix ADC VPX Vulnerabilidades:
Evaluación gratuita de vulnerabilidades
Compare su postura de seguridad en la nube
Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.
Recursos adicionales de Wiz
Obtén una demostración personalizada
¿Listo para ver a Wiz en acción?
"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."