CitrixBleed 2 — نشت حافظه در Citrix NetScaler ADC
- شناسه CVE: CVE-2025-5777
- شدت: بحرانی
- امتیاز CVSS: 9.4
- فروشنده/سازنده: Citrix
Memory LeakVPNCitrixKEVSession Hijack
CitrixBleed 2 is a critical buffer over-read vulnerability in Citrix NetScaler ADC and Gateway appliances, representing a dangerous evolution of the original CitrixBleed (CVE-2023-4966).
## Vulnerability Overview
The vulnerability allows an unauthenticated remote attacker to read sensitive memory contents from the NetScaler appliance, including valid session tokens for authenticated VPN sessions. By replaying these stolen tokens, an attacker can hijack active VPN sessions and gain full access to the internal corporate network.
## Technical Details
- **Vulnerability Type:** Buffer Over-read / Out-of-Bounds Read (CWE-125)
- **Affected Service:** HTTPS virtual server / Gateway virtual server
- **Root Cause:** Improper bounds checking in the HTTP/2 header processing logic. When processing specially crafted HTTP/2 HEADERS frames, the appliance reads beyond the allocated buffer, leaking adjacent memory contents.
- **Memory Leaked:** Session cookies (NSC_AAAC), authentication tokens, and potentially other sensitive data from kernel memory.
## Exploitation Details
- Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Active internet-wide scanning for vulnerable instances has been observed.
- Mass exploitation campaigns targeting financial institutions and government agencies reported.
- Average time from initial access to lateral movement: under 2 hours.
## Affected Versions
- Citrix NetScaler ADC 14.1 before 14.1-12.35
- Citrix NetScaler ADC 13.1 before 13.1-51.15
- Citrix NetScaler Gateway (same versions)
## Indicators of Compromise (IOCs)
- Unusual GET requests to /vpn/index.html with oversized headers
- Multiple sessions from different geographic locations for the same user
- Unexpected VPN tunnel creation logs
## Vulnerability Overview
The vulnerability allows an unauthenticated remote attacker to read sensitive memory contents from the NetScaler appliance, including valid session tokens for authenticated VPN sessions. By replaying these stolen tokens, an attacker can hijack active VPN sessions and gain full access to the internal corporate network.
## Technical Details
- **Vulnerability Type:** Buffer Over-read / Out-of-Bounds Read (CWE-125)
- **Affected Service:** HTTPS virtual server / Gateway virtual server
- **Root Cause:** Improper bounds checking in the HTTP/2 header processing logic. When processing specially crafted HTTP/2 HEADERS frames, the appliance reads beyond the allocated buffer, leaking adjacent memory contents.
- **Memory Leaked:** Session cookies (NSC_AAAC), authentication tokens, and potentially other sensitive data from kernel memory.
## Exploitation Details
- Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Active internet-wide scanning for vulnerable instances has been observed.
- Mass exploitation campaigns targeting financial institutions and government agencies reported.
- Average time from initial access to lateral movement: under 2 hours.
## Affected Versions
- Citrix NetScaler ADC 14.1 before 14.1-12.35
- Citrix NetScaler ADC 13.1 before 13.1-51.15
- Citrix NetScaler Gateway (same versions)
## Indicators of Compromise (IOCs)
- Unusual GET requests to /vpn/index.html with oversized headers
- Multiple sessions from different geographic locations for the same user
- Unexpected VPN tunnel creation logs
نرمافزارهای تحت تأثیر
- Citrix NetScaler ADC
- Citrix Gateway