Ò»¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | NetScalerÄÚ´æÒç³öÔ¶³Ì´úÂëÖ´Ðзì϶ |
CVE ID | CVE-2025-7775 |
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-08-27 |
·ì϶ÆÀ·Ö | 9.2 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
NetScaler ADC£¨Ç°³ÆCitrix ADC£©ºÍNetScaler Gateway£¨Ç°³ÆCitrix Gateway£©ÊÇÓÉCitrix¹«Ë¾ÌṩµÄ¸ß»úÄÜÀûÓý»¸¶ºÍÔ¶³Ì½Ó¼û½â¾ö¹æ»®¡£NetScaler ADCÖ¼ÔÚÓÅ»¯ÀûÓûúÄÜ¡¢Ìá¸ß¿ÉÓÃÐÔ²¢¼ÓÇ¿°²È«ÐÔ£¬£¬£¬¿í·ºÓÃÓÚ¸ºÔØÆ½ºâ¡¢ÄÚÈÝ»º´æºÍÀûÓüӿìµÈÁìÓò¡£NetScaler GatewayÔòרһÓÚΪԶ³ÌÓû§Ìṩ°²È«µÄÐ鹹רÓÃÍøÂ磨VPN£©½Ó¼û£¬£¬£¬Ö§³Ö¶à³É·ÖÈÏÖ¤ºÍµ¥µãµÇ¼£¨SSO£©µÈÖ°ÄÜ¡£Á½Õß¶¼¿ÉÄÜÔ®ÊÖÆóÒµÔÚ±£ÕÏÀûÓý»¸¶Ð§ÄܵÄͬʱ£¬£¬£¬È·±£Êý¾Ý´«ÊäºÍÓû§½Ó¼ûµÄ°²È«ÐÔ¡£
2025Äê8ÔÂ27ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½NetScaler ADCºÍNetScaler Gateway´æÔÚÄÚ´æÒç³öÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-7775)¡£¹¥»÷Õß¿Éͨ¹ý»ú¹ØÌØÖÆÒªÇó´¥·¢ÄÚ´æÒç³ö£¬£¬£¬´Ó¶øÖ´ÐÐËÁÒâ´úÂë»òµ¼ÖÂϵͳ±ÀÀ££¬£¬£¬ÑÏÖØÍþвҵÎñÂ½ÐøÐÔÓëÊý¾Ý°²È«¡£¸Ã·ì϶ӰÏìÅäÖÃÎªÍø¹Ø£¨VPNÐé¹¹·þÎñÆ÷¡¢ICA Proxy¡¢CVPN¡¢RDP Proxy£©»òAAAÐé¹¹·þÎñÆ÷µÄÉ豸£»£»£»Í¬Ê±Ò²Ó°ÏìÔËÐÐ13.1¡¢14.1¡¢13.1-FIPSºÍNDcPP°æ±¾µÄNetScaler£¬£¬£¬ÔÚÒÔÏÂÈÎһǰÌáϾù´æÔÚ·çÏÕ£º£º£º¢Ù¸ºÔØÆ½ºâ£¨LB£©Ðé¹¹·þÎñÆ÷ÀàÐÍΪHTTP¡¢SSL»òHTTP_QUIC£¬£¬£¬ÇÒ°ó¶¨IPv6·þÎñ»òÓëIPv6·þÎñÆ÷µÄ·þÎñ×飻£»£»¢ÚLBÐé¹¹·þÎñÆ÷°ó¶¨DBS IPv6·þÎñ»òÓëIPv6 DBS·þÎñÆ÷µÄ·þÎñ×飻£»£»¢ÛÅäÖÃΪHDXÀàÐ͵ÄCRÐé¹¹·þÎñÆ÷¡£
¶þ¡¢Ó°ÏìÁìÓò
13.1 <= NetScaler ADC\NetScaler Gateway < 13.1-59.2214.1 <= NetScaler ADC\NetScaler Gateway < 14.1-47.4813.1-FIPS <= NetScaler ADC\NetScaler Gateway < 13.1-37.24113.1-NDcPP <= NetScaler ADC\NetScaler Gateway < 13.1-37.24112.1-FIPS <= NetScaler ADC\NetScaler Gateway < 12.1-55.33012.1-NDcPP <= NetScaler ADC\NetScaler Gateway < 12.1-55.330¡£
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼°²È«²¹¶¡£¬£¬£¬Éý¼¶ÖÁÈçϰ汾¡£NetScaler ADC\NetScaler Gateway >= 14.1-47.48NetScaler ADC\NetScaler Gateway >= 13.1-59.22NetScaler ADC\NetScaler Gateway (13.1-FIPS) >= 13.1-37.241NetScaler ADC\NetScaler Gateway (13.1-NDcPP) >= 13.1-37.241NetScaler ADC\NetScaler Gateway (12.1-FIPS) >= 12.1-55.330NetScaler ADC\NetScaler Gateway (12.1-NDcPP) >= 12.1-55.330NetScaler ADC / Gateway 12.1 ͨ³£°æÓë 13.0 ȫϵÁÐÒÑ´ïµ½ÐÔÃüÖÜÆÚÖÕÖ¹£¨EOL£©£¬£¬£¬²»ÔÙÌṩ°²È«²¹¶¡£¬£¬£¬½¨ÒéÖ±½ÓÉý¼¶ÖÁÊÜÖ§³ÖµÄ°²È«°æ±¾£¬£¬£¬²¢ÓÅÏÈ˼¿¼Éý¼¶µ½ 14.1 ϵÁм°ÒÔÉϰ汾£¬£¬£¬ÒÔ»ñµÃ³Ö¾ÃÖ§³ÖºÍ×îа²È«ÐÞ¸´¡£
3.2 һʱ´ëÊ©
ÖÎÀíÔ±¿Éͨ¹ýÔÚ NetScaler ÅäÖÃÖÐËÑË÷ÒÔϺÅÁ£¬£¬È·ÈÏÉ豸ÊÇ·ñ´¦ÓÚÊÜÓ°Ïì״̬£º£º£º²é³ AAA Ðé¹¹·þÎñÆ÷£¨Auth Server£©show run | grep "add authentication vserver"Èô·¢ÏÖÅäÖÃÁË AAA Ðé¹¹·þÎñÆ÷£¬£¬£¬ÇÒµ±Ç°Î´Ê¹Ó㬣¬£¬½¨Òéһʱ½ûÓá£²é³ Gateway£¨VPN / ICA Proxy / CVPN / RDP Proxy£©show run | grep "add vpn vserver"ÈçδʹÓà VPN Ö°ÄÜ£¬£¬£¬½¨ÒéÁÙʱ¹Ø±ÕÓйØÐé¹¹·þÎñÆ÷»òÏ޶ȽӼû¡£²é³¸ºÔØÆ½ºâ£¨LB£©Ðé¹¹·þÎñÆ÷°ó¶¨ IPv6 ·þÎñshow run | grep "add lb vserver"show run | grep "add serviceGroup"show run | grep "add server"ÖØµãÅŲé HTTP¡¢SSL¡¢HTTP_QUIC ÀàÐ굀 LB Ðé¹¹·þÎñÆ÷£¬£¬£¬Èô°ó¶¨ IPv6 ·þÎñ»ò IPv6 ·þÎñ×飬£¬£¬´æÔÚÊܹ¥»÷·çÏÕ¡£²é³°ó¶¨ DBS IPv6 ·þÎñ»ò·þÎñÆ÷show run | grep "add server .* -queryType AAAA"show run | grep "bind servicegroup"Èç²»±ØÒª IPv6 DBS ½âÎö·þÎñ£¬£¬£¬½¨ÒéÁ¢¼´½â°ó»ò½ûÓá£²é³ CR Ðé¹¹·þÎñÆ÷£¨HDX ÀàÐÍ£©show run | grep "add cr vserver"ÈôδʹÓà HDX ÀàÐÍ CR Ðé¹¹·þÎñÆ÷£¬£¬£¬¿Éһʱ½ûÓ᣶ÔÓÚδʹÓÃµÄ AAA¡¢VPN¡¢ICA Proxy¡¢CVPN¡¢RDP Proxy¡¢HDX ÀàÐÍ CR Ðé¹¹·þÎñÆ÷µÈ¸ß·çÏÕÅäÖ㬣¬£¬½¨ÒéÁ¢¼´½ûÓ㺣º£ºdisable authentication vserverÈôÒµÎñÔÊÐí£¬£¬£¬¿ÉÔÚÊÜÓ°ÏìµÄ LB Ðé¹¹·þÎñÆ÷ÉϽâ°ó IPv6 ·þÎñ»ò¹Ø±Õ IPv6 Ö°ÄÜ£º£º£ºset ns param -ipv6 DISABLEDÔÚ·À»ðǽ¡¢WAF »ò ACL ÖÐÏ޶ȶÔÊÜÓ°ÏìÉ豸µÄ¹«Íø½Ó¼û£¬£¬£¬½öÔÊÐí¿ÉÐÅÖÎÀí IP ¶Î¡£½¨ÒéÓÅÏÈͨ¹ýÄÚÍø»ò VPN °²È«Í¨µÀÖÎÀíÉ豸¡£¿ªÆô NetScaler °²È«ÈÕÖ¾Ö°ÄÜ£¬£¬£¬Öصã¼à¿ØÒì³£ÒªÇó¡¢IPv6 °ó¶¨Å²ÓõȿÉÒÉÐÐΪ¡£¹²Í¬ SIEM / IDS / NDR ¹¤¾ß£¬£¬£¬ÊµÊ±¼ì²âDZÔÚ¹¥»÷¼£Ïó¡£
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£? ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938/https://nvd.nist.gov/vuln/detail/CVE-2025-7775