ZeroHour

CVE-2025-12101

mass

Cross-Site Scripting in Citrix NetScaler ADC and NetScaler Gateway

CVSS 4.0
5.9 medium
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2025-12101 is a cross-site scripting (XSS, CWE-79) flaw in Citrix NetScaler ADC and NetScaler Gateway that affects appliances only when they are configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. An attacker can craft input that, when rendered to a user (the CVSS 4.0 vector requires user interaction but no privileges), executes attacker-supplied script in the victim's browser session in the context of the Gateway or AAA pages, with high confidentiality impact per the scoring. Successful exploitation could expose session data or credentials handled through the VPN/AAA portal, but the impact scope is limited to the affected system with low integrity and availability impact. Deployments of NetScaler ADC or NetScaler Gateway that do not use Gateway or AAA virtual servers are not affected. No public proof of concept or confirmed in-the-wild exploitation is known and it is not yet in CISA KEV, but the EPSS score of 25.4% (98th percentile) indicates a significant likelihood of exploitation within 30 days.

What to do: Identify all NetScaler ADC/Gateway appliances with Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers — especially internet-reachable VPN portals — and upgrade them to the fixed builds listed in the Citrix security bulletin for CVE-2025-12101 (exact fixed versions are not included in this data). As interim measures, restrict untrusted access to the Gateway/AAA endpoints and monitor for exploitation attempts, prioritizing patching given the high EPSS likelihood despite the lack of known in-the-wild exploitation.

Affected
Citrix NetScaler ADC
Citrix NetScaler Gateway
Estimated exposure
mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances, serving likely millions of remote VPN users — NetScaler ADC/Gateway is one of the most widely deployed enterprise VPN/edge appliance platforms, and public internet-wide scans (e.g., Shodan/Censys) have historically shown on the order of 100k+ exposed NetScaler instances, most of which…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.