Citrix issued a warning about a vulnerability in its NetScaler Application Delivery Controller (ADC) and Gateway platforms that could be exploited by denial of service (DoS) attacks, a vulnerability that comes hot on the heels of a recent return of the so-called "CitrixBleed" flaw.
Citrix published a "critical" level security bulletin, dubbed "CVE-2025-6543," which the vendor noted leaves Netscaler devices susceptible to DoS attacks.
The vulnerability impacts NetScaler ADC and NetScaler Gateway devices, and if triggered by unauthenticated and remote requests could bring appliances offline. Citrix recommends that administrators update their NetScaler systems with updates that patch the issues from previous versions.
The flaw comes just over a week after the return of "CitrixBleed 2." Officially designated "CVE-2025-6543," the flaw is similar to the initial vulnerability from 2023, CitrixBleed, in that it allowed unauthenticated attackers to seize session-authentication cookies. The CitrixBleed 2 flaw Impacts Citrix NetScaler ADC and NetScaler Gateway devices, with a root cause is put down to out-of-bounds memory read.
Citrix recommends users terminate all active ICA and PCoIP sessions upon update. Patches are not available for those on end-of-life systems.
Exploitation of the original CitrixBleed led to ransomware and government attacks. It’s unclear yet on what damage the sequel has caused, but it is clear that the flaw was able to be exploited in the wild before a fix was released.
The underlying issue is one of memory overflow in C-based code; this can arguably only be fixed by moving network infrastructure to memory-safe languages, as recommended just this week by CISA.
Comments