
PEACH
Un cadre d’isolation des locataires
A memory overflow vulnerability (CVE-2025-7776) was discovered in NetScaler ADC and NetScaler Gateway that could lead to unpredictable or erroneous behavior and Denial of Service when NetScaler is configured as a Gateway with PCoIP Profile bounded to it. The vulnerability was disclosed on August 26, 2025, affecting multiple versions of NetScaler ADC and NetScaler Gateway (NVD, Hacker News).
The vulnerability has been assigned a CVSS v4.0 base score of 8.8 (High) with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L. The vulnerability is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). For exploitation, NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it (NVD).
When successfully exploited, the vulnerability can result in unpredictable system behavior and Denial of Service conditions in the affected NetScaler appliances. This could potentially disrupt critical network services and impact business operations (Hacker News).
Citrix has released patches to address this vulnerability. The fixed versions include: NetScaler ADC and NetScaler Gateway 14.1-47.48 and later releases, NetScaler ADC and NetScaler Gateway 13.1-59.22 and later releases of 13.1, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.241 and later releases, and NetScaler ADC 12.1-FIPS and 12.1-NDcPP 12.1-55.330 and later releases (Hacker News).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."