# CVE-2025-8424

## Summary

- **CVE ID:** CVE-2025-8424
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)
- **CWE:** CWE-1284
- **Published:** Aug 26, 2025
- **Last Modified:** Mar 12, 2026

## Description

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access

## Affected Products

- NetScaler — ADC (14.1)
- NetScaler — ADC (13.1)
- NetScaler — ADC (13.1 FIPS and NDcPP)
- NetScaler — ADC (12.1 FIPS and NDcPP)
- NetScaler — Gateway (14.1)
- NetScaler — Gateway (13.1)
- NetScaler — Gateway (13.1 FIPS and NDcPP)
- NetScaler — Gateway (12.1 FIPS and NDcPP)

## References

- [CNA](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.82%
- **EPSS Percentile:** 85.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._