CVE-2025-4365
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-06-17
Last updated on: 2025-08-06
Assigner: Citrix Systems, Inc.
Description
Description
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 13.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_console | 14.1 |
| citrix | netscaler_sdx | From 13.1-49.13 (inc) to 13.1-58.32 (exc) |
| citrix | netscaler_sdx | From 14.1-4.42 (inc) to 14.1-47.46 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an arbitrary file read issue in NetScaler Console and NetScaler SDX (SVM), which means an attacker with certain privileges can read files on the system that they should not have access to.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker could potentially access sensitive files on the affected systems, leading to information disclosure and possible further exploitation depending on the contents of those files.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70