---
cve: "CVE-2025-6543"
severity: "CRITICAL"
cvss: 9.2
epss: "10.1%"
vendor: "NetScaler"
kev: true
exploited: true
published: "2025-06-25 13:15:27"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T08:38:50+02:00"
---

# CVE-2025-6543

> 9.2 CRITICAL · ⚠️ CISA KEV (430 Tage) · 🔓 Exploited

## Beschreibung

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6543>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-6543) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
