¡¾·ì϶¹«¸æ¡¿Citrix NetScaler ÄÚ´æÐ¹Â©·ì϶ (CVE-2025-5777)

°ä²¼¹¦·ò 2025-07-11

Ò»¡¢¡¢·ì϶¸ÅÊö


·ì϶Ãû³Æ

Citrix NetScaler ÄÚ´æÐ¹Â©·ì϶

CVE   ID

CVE-2025-5777

·ì϶ÀàÐÍ

ÄÚ´æÐ¹Â©

·¢ÏÖ¹¦·ò

2025-07-11

·ì϶ÆÀ·Ö

9.3

·ì϶µÈ¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


NetScaler ADC£¨Ç°³ÆCitrix ADC£©ºÍNetScaler Gateway£¨Ç°³ÆCitrix Gateway£©ÊÇÓÉCitrix¹«Ë¾ÌṩµÄ¸ß»úÄÜÀûÓý»¸¶ºÍÔ¶³Ì½Ó¼û½â¾ö¹æ»®¡£¡£NetScaler ADCÖ¼ÔÚÓÅ»¯ÀûÓûúÄÜ¡¢¡¢Ìá¸ß¿ÉÓÃÐÔ²¢¼ÓÇ¿°²È«ÐÔ£¬£¬£¬¿í·ºÓÃÓÚ¸ºÔØÆ½ºâ¡¢¡¢ÄÚÈÝ»º´æºÍÀûÓüӿìµÈÁìÓò¡£¡£NetScaler GatewayÔòרһÓÚΪԶ³ÌÓû§Ìṩ°²È«µÄÐ鹹רÓÃÍøÂ磨VPN£©½Ó¼û£¬£¬£¬Ö§³Ö¶à³É·ÖÈÏÖ¤ºÍµ¥µãµÇ¼£¨SSO£©µÈÖ°ÄÜ¡£¡£Á½Õß¶¼¿ÉÄÜÔ®ÊÖÆóÒµÔÚ±£ÕÏÀûÓý»¸¶Ð§ÄܵÄͬʱ£¬£¬£¬È·±£Êý¾Ý´«ÊäºÍÓû§½Ó¼ûµÄ°²È«ÐÔ¡£¡£


2025Äê7ÔÂ11ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Citrix NetScaler ·¢ÏÖÁËÒ»¸öÑÏÖØµÄÄÚ´æÐ¹Â©·ì϶£¬£¬£¬Ó°Ïì¶à¸ö°æ±¾µÄNetScaler ADCºÍNetScaler Gateway¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔ¶³Ì¡¢¡¢Î´¾­Éí·ÝÑéÖ¤µÄ·½Ê½£¬£¬£¬¶ÁÈ¡É豸ÄÚ´æÖеÄÃô¸ÐÐÅÏ¢£¬£¬£¬Èç»á»°ÁîÅÆ£¬£¬£¬´Ó¶øÈƹý¶à³É·ÖÈÏÖ¤£¨MFA£©»úÖÆ²¢½Ù³ÖÓû§»á»°¡£¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜ»ñµÃδ¾­ÊÚȨµÄ½Ó¼ûȨÏÞ£¬£¬£¬½øÒ»²½Î£¼°ÆóÒµ¹Ø¼üϵͳµÄ°²È«ÐÔ¡£¡£¸Ã·ì϶²»½ö¿ÉÄܵ¼ÖÂÊý¾Ýй¶£¬£¬£¬»¹¿ÉÄÜʹ¹¥»÷Õß»ñµÃ¶ÔÊÜÓ°ÏìϵͳµÄÆëÈ«½ÚÖÆ£¬£¬£¬´Ó¶øÒý·¢¸ü¿í·ºµÄ°²È«·çÏÕ¡£¡£


¶þ¡¢¡¢Ó°ÏìÁìÓò


NetScaler ADC 14.1 < 14.1-43.56
NetScaler Gateway 14.1 < 14.1-43.56
NetScaler ADC < 13.1-58.32
NetScaler Gateway 13.1 < 13.1-58.32
NetScaler ADC 13.1-FIPS < 13.1-37.235-FIPS
NetScaler ADC 13.1-FIPS < 13.1-37.235-NDcPP
NDcPP < 13.1-37.235-FIPS
NDcPP < 13.1-37.235-NDcPP
NetScaler ADC 12.1-FIPS < 12.1-55.328-FIPS
NetScaler ADC ºÍ NetScaler Gateway °æ±¾ 12.1 ºÍ 13.0 ÒѽøÈëÐÔÃüÖÜÆÚʵÏÖ£¨EOL£©£¬£¬£¬²¢ÇÒ´æÔÚ·ì϶£¬£¬£¬´ËÍ⣬£¬£¬ËùÓÐʹÓà NetScaler ʵÀýµÄ Secure Private Access ²¿Êð¾ùÊÜ´Ë·ì϶ӰÏì¡£¡£


Èý¡¢¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼ÐÞ¸´°æ±¾£¬£¬£¬½¨ÒéÓû§Éý¼¶ÖÁÈçϰ汾
NetScaler ADC >= 14.1-43.56
NetScaler Gateway >= 14.1-43.56
NetScaler ADC >= 13.1-58.32
NetScaler Gateway >= 13.1-58.32
NetScaler ADC 13.1-FIPS >= 13.1-37.235-FIPS
NDcPP >= 13.1-37.235-FIPS
NetScaler ADC 12.1-FIPS >= 12.1-55.328-FIPS


´ËÍ⣬£¬£¬ÔÚËùÓÐ NetScaler É豸£¨Ô̺¬ HA ¶Ô»ò¼¯Èº£©Éý¼¶ÖÁÐÞ¸´°æ±¾ºó£¬£¬£¬½¨ÒéÔËÐÐÒÔϺÅÁîÒÔÖÕÖ¹ËùÓлµÄ ICA ºÍ PCoIP »á»°£º£º£º

kill icaconnection -all
kill pcoipConnection -all
°ÑÎÈ£º£º£ºNetScaler ADC ºÍ NetScaler Gateway °æ±¾ 12.1 ºÍ 13.0 ÒÑÖÕ³¡Ö§³Ö£¨EOL£©£¬£¬£¬²»ÔÙÊÜÖ§³Ö¡£¡£


ÏÂÔØÁ´½Ó£º£º£ºhttps://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£


3.4 ²Î¿¼Á´½Ó


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
https://www.theregister.com/2025/07/07/citrixbleed_2_exploits/
https://nvd.nist.gov/vuln/detail/CVE-2025-5777