¡¾·ì϶¹«¸æ¡¿Citrix NetScaler ÄÚ´æÐ¹Â©·ì϶ (CVE-2025-5777)

°ä²¼¹¦·ò 2025-07-11

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Citrix NetScaler ÄÚ´æÐ¹Â©·ì϶

CVE   ID

CVE-2025-5777

·ì϶ÀàÐÍ

ÄÚ´æÐ¹Â©

·¢ÏÖ¹¦·ò

2025-07-11

·ì϶ÆÀ·Ö

9.3

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


NetScaler ADC£¨Ç°³ÆCitrix ADC£©ºÍNetScaler Gateway£¨Ç°³ÆCitrix Gateway£©ÊÇÓÉCitrix¹«Ë¾ÌṩµÄ¸ß»úÄÜÀûÓý»¸¶ºÍÔ¶³Ì½Ó¼û½â¾ö¹æ»®¡£NetScaler ADCÖ¼ÔÚÓÅ»¯ÀûÓûúÄÜ¡¢Ìá¸ß¿ÉÓÃÐÔ²¢¼ÓÇ¿°²È«ÐÔ£¬¿í·ºÓÃÓÚ¸ºÔØÆ½ºâ¡¢ÄÚÈÝ»º´æºÍÀûÓüӿìµÈÁìÓò¡£NetScaler GatewayÔòרһÓÚΪԶ³ÌÓû§Ìṩ°²È«µÄÐ鹹רÓÃÍøÂ磨VPN£©½Ó¼û£¬Ö§³Ö¶à³É·ÖÈÏÖ¤ºÍµ¥µãµÇ¼£¨SSO£©µÈÖ°ÄÜ¡£Á½Õß¶¼¿ÉÄÜÔ®ÊÔìóÒµÔÚ±£ÕÏÀûÓý»¸¶Ð§ÄܵÄͬʱ£¬È·±£Êý¾Ý´«ÊäºÍÓû§½Ó¼ûµÄ°²È«ÐÔ¡£


2025Äê7ÔÂ11ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Citrix NetScaler ·¢ÏÖÁËÒ»¸öÑϳÁµÄÄÚ´æÐ¹Â©·ì϶£¬Ó°Ïì¶à¸ö°æ±¾µÄNetScaler ADCºÍNetScaler Gateway¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔ¶³Ì¡¢Î´¾­Éí·ÝÑéÖ¤µÄ·½Ê½£¬¶ÁÈ¡É豸ÄÚ´æÖеÄÃô¸ÐÐÅÏ¢£¬Èç»á»°ÁîÅÆ£¬´Ó¶øÈƹý¶à³É·ÖÈÏÖ¤£¨MFA£©»úÔì²¢½Ù³ÖÓû§»á»°¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜ»ñµÃδ¾­ÊÚȨµÄ½Ó¼ûȨÏÞ£¬½øÒ»²½Î£¼°ÆóÒµ¹Ø¼üϵͳµÄ°²È«ÐÔ¡£¸Ã·ì϶²»½ö¿ÉÄܵ¼ÖÂÊý¾Ýй¶£¬»¹¿ÉÄÜʹ¹¥»÷Õß»ñµÃ¶ÔÊÜÓ°ÏìϵͳµÄÆëÈ«½ÚÔ죬´Ó¶øÒý·¢¸ü¿í·ºµÄ°²È«·çÏÕ¡£


¶þ¡¢Ó°ÏìÁìÓò


NetScaler ADC 14.1 < 14.1-43.56
NetScaler Gateway 14.1 < 14.1-43.56
NetScaler ADC < 13.1-58.32
NetScaler Gateway 13.1 < 13.1-58.32
NetScaler ADC 13.1-FIPS < 13.1-37.235-FIPS
NetScaler ADC 13.1-FIPS < 13.1-37.235-NDcPP
NDcPP < 13.1-37.235-FIPS
NDcPP < 13.1-37.235-NDcPP
NetScaler ADC 12.1-FIPS < 12.1-55.328-FIPS
NetScaler ADC ºÍ NetScaler Gateway °æ±¾ 12.1 ºÍ 13.0 ÒѽøÈëÐÔÃüÖÜÆÚʵÏÖ£¨EOL£©£¬²¢ÇÒ´æÔÚ·ì϶£¬´Ë±í£¬ËùÓÐʹÓà NetScaler Ê·ýµÄ Secure Private Access ²¿Êð¾ùÊÜ´Ë·ì϶ӰÏì¡£


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´°æ±¾£¬½¨ÒéÓû§Éý¼¶ÖÁÈçϰ汾
NetScaler ADC >= 14.1-43.56
NetScaler Gateway >= 14.1-43.56
NetScaler ADC >= 13.1-58.32
NetScaler Gateway >= 13.1-58.32
NetScaler ADC 13.1-FIPS >= 13.1-37.235-FIPS
NDcPP >= 13.1-37.235-FIPS
NetScaler ADC 12.1-FIPS >= 12.1-55.328-FIPS


´Ë±í£¬ÔÚËùÓÐ NetScaler É豸£¨Ô̺¬ HA ¶Ô»ò¼¯Èº£©Éý¼¶ÖÁ½¨¸´°æ±¾ºó£¬½¨ÒéÔËÐÐÒÔϺÅÁîÒÔÖÕÖ¹ËùÓлµÄ ICA ºÍ PCoIP »á»°£º

kill icaconnection -all
kill pcoipConnection -all
°ÑÎÈ£ºNetScaler ADC ºÍ NetScaler Gateway °æ±¾ 12.1 ºÍ 13.0 ÒÑÖÕ³¡Ö§³Ö£¨EOL£©£¬²»ÔÙÊÜÖ§³Ö¡£


ÏÂÔØÁ´½Ó£ºhttps://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
https://www.theregister.com/2025/07/07/citrixbleed_2_exploits/
https://nvd.nist.gov/vuln/detail/CVE-2025-5777