CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
Em resumo
NetScaler ADC e NetScaler Gateway possuem uma falha onde não validam adequadamente dados de entrada, permitindo que atacantes leiam informações da memória que não deveriam acessar. Isso é perigoso porque pode expor informações sensíveis como senhas ou chaves de criptografia.
Detalhe técnico
Validação insuficiente de entrada em NetScaler Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) e servidores AAA virtuais permite leitura de memória fora dos limites (CWE-125, CWE-457). Um atacante pode enviar dados malformados para disparar leitura de memória não autorizada, potencialmente divulgando dados sensíveis sem necessidade de autenticação ou privilégios especiais, conforme a configuração específica.
Resumo gerado e traduzido por IA a partir da descrição oficial.
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
PoCs públicas encontradas — 24
githubgithub.com/win3zz/CVE-2025-5777★ 47githubgithub.com/bughuntar/CVE-2025-5777★ 30githubgithub.com/mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-★ 17githubgithub.com/Chocapikk/CVE-2025-5777★ 7githubgithub.com/Shivshantp/CVE-2025-5777-TrendMicro-ApexCentral-RCE★ 4githubgithub.com/soltanali0/CVE-2025-5777-Exploit★ 4githubgithub.com/nocerainfosec/cve-2025-5777★ 3githubgithub.com/ndr-repo/CVE-2025-5777★ 3githubgithub.com/orange0Mint/CitrixBleed-2-CVE-2025-5777★ 2githubgithub.com/cyberleelawat/ExploitVeer★ 2githubgithub.com/RickGeex/CVE-2025-5777-CitrixBleed★ 1githubgithub.com/0xBlackash/CVE-2025-5777★ 0githubgithub.com/mr-r3b00t/CVE-2025-5777★ 0githubgithub.com/idobarel/CVE-2025-5777★ 0githubgithub.com/RaR1991/citrix_bleed_2★ 0githubgithub.com/FrenzisRed/CVE-2025-5777★ 0githubgithub.com/0xgh057r3c0n/CVE-2025-5777★ 0githubgithub.com/SleepNotF0und/CVE-2025-5777★ 0githubgithub.com/rob0tstxt/POC-CVE-2025-5777★ 0githubgithub.com/below0day/Honeypot-Logs-CVE-2025-5777★ 0githubgithub.com/rootxsushant/Citrix-NetScaler-Memory-Leak-CVE-2025-5777★ 0githubgithub.com/Anshika2709/Citrixbleed2-CVE-2025-5777★ 0githubgithub.com/rashedhasan090/CVE-2025-5777★ 0exploitdbwww.exploit-db.com/exploits/52401não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://citrixbleed.comhttps://doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/https://reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/