CVE-2025-12101 Details
Description
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
A Cross-Site Scripting (XSS) vulnerability has been identified in Citrix NetScaler ADC and NetScaler Gateway. This issue arises when the appliance is set up as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. The vulnerability is present in specific versions of both products, as detailed in the security bulletin.
Affected customers should upgrade to NetScaler ADC and NetScaler Gateway versions 14.1-56.73, 13.1-60.32, 13.1-37.250-FIPS and NDcPP, or 12.1-55.333-FIPS and NDcPP. Note that versions 12.1 and 13.0 are End Of Life and no longer supported.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 11, 2025CISA-ADP
Assessed Nov 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX695486 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Citrix NetScaler ADC | < 14.1-56.73 < 13.1-60.32 < 13.1-37.250-FIPS < 12.1-55.333-FIPS ~12.1 ~13.0 |
CPE
Remediation
| |
| Citrix NetScaler Gateway | < 14.1-56.73 < 13.1-60.32 < 13.1-37.250-FIPS < 12.1-55.333-FIPS ~12.1 ~13.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 11, 2025 | New CVE Received | [email protected] |
Volerion