¡¾Îó²îͨ¸æ¡¿NetScalerÄÚ´æÒç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-7775)

Ðû²¼Ê±¼ä 2025-08-27

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

NetScalerÄÚ´æÒç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-7775

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-08-27

Îó²îÆÀ·Ö

9.2

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

¸ß

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

ÒÑ·¢Ã÷


NetScaler ADC£¨Ç°³ÆCitrix ADC£©ºÍNetScaler Gateway£¨Ç°³ÆCitrix Gateway£©ÊÇÓÉCitrix¹«Ë¾ÌṩµÄ¸ßÐÔÄÜÓ¦Óý»¸¶ºÍÔ¶³Ì»á¿´·¨¾ö¼Æ»® ¡£¡£¡£¡£¡£NetScaler ADCÖ¼ÔÚÓÅ»¯Ó¦ÓÃÐÔÄÜ¡¢Ìá¸ß¿ÉÓÃÐÔ²¢ÔöÇ¿Çå¾²ÐÔ£¬£¬ £¬£¬£¬£¬ÆÕ±éÓÃÓÚ¸ºÔØÆ½ºâ¡¢ÄÚÈÝ»º´æºÍÓ¦ÓüÓËÙµÈÁìÓò ¡£¡£¡£¡£¡£NetScaler GatewayÔòרעÓÚΪԶ³ÌÓû§ÌṩÇå¾²µÄÐéÄâרÓÃÍøÂ磨VPN£©»á¼û£¬£¬ £¬£¬£¬£¬Ö§³Ö¶àÒòËØÈÏÖ¤ºÍµ¥µãµÇ¼£¨SSO£©µÈ¹¦Ð§ ¡£¡£¡£¡£¡£Á½Õß¶¼Äܹ»×ÊÖúÆóÒµÔÚ°ü¹ÜÓ¦Óý»¸¶Ð§ÂʵÄͬʱ£¬£¬ £¬£¬£¬£¬È·±£Êý¾Ý´«ÊäºÍÓû§»á¼ûµÄÇå¾²ÐÔ ¡£¡£¡£¡£¡£


2025Äê8ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½NetScaler ADCºÍNetScaler Gateway±£´æÄÚ´æÒç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-7775) ¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹ÌØÖÆÇëÇó´¥·¢ÄÚ´æÒç³ö£¬£¬ £¬£¬£¬£¬´Ó¶øÖ´ÐÐí§Òâ´úÂë»òµ¼ÖÂϵͳÍ߽⣬£¬ £¬£¬£¬£¬ÑÏÖØÍþвӪҵһÁ¬ÐÔÓëÊý¾ÝÇå¾² ¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÉèÖÃÎªÍø¹Ø£¨VPNÐéÄâЧÀÍÆ÷¡¢ICA Proxy¡¢CVPN¡¢RDP Proxy£©»òAAAÐéÄâЧÀÍÆ÷µÄ×°±¸£»£»£»£»Í¬Ê±Ò²Ó°ÏìÔËÐÐ13.1¡¢14.1¡¢13.1-FIPSºÍNDcPP°æ±¾µÄNetScaler£¬£¬ £¬£¬£¬£¬ÔÚÒÔÏÂÈÎÒ»Ìõ¼þϾù±£´æÎ£º¦£º¢Ù¸ºÔØÆ½ºâ£¨LB£©ÐéÄâЧÀÍÆ÷ÀàÐÍΪHTTP¡¢SSL»òHTTP_QUIC£¬£¬ £¬£¬£¬£¬ÇÒ°ó¶¨IPv6ЧÀÍ»òÓëIPv6ЧÀÍÆ÷µÄЧÀÍ×飻£»£»£»¢ÚLBÐéÄâЧÀÍÆ÷°ó¶¨DBS IPv6ЧÀÍ»òÓëIPv6 DBSЧÀÍÆ÷µÄЧÀÍ×飻£»£»£»¢ÛÉèÖÃΪHDXÀàÐ͵ÄCRÐéÄâЧÀÍÆ÷ ¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


13.1 <= NetScaler ADC\NetScaler Gateway < 13.1-59.22
14.1 <= NetScaler ADC\NetScaler Gateway < 14.1-47.48
13.1-FIPS <= NetScaler ADC\NetScaler Gateway < 13.1-37.241
13.1-NDcPP <= NetScaler ADC\NetScaler Gateway < 13.1-37.241
12.1-FIPS <= NetScaler ADC\NetScaler Gateway < 12.1-55.330
12.1-NDcPP <= NetScaler ADC\NetScaler Gateway < 12.1-55.330 ¡£¡£¡£¡£¡£


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬£¬ £¬£¬£¬£¬Éý¼¶ÖÁÈçϰ汾 ¡£¡£¡£¡£¡£
NetScaler ADC\NetScaler Gateway >= 14.1-47.48
NetScaler ADC\NetScaler Gateway >= 13.1-59.22
NetScaler ADC\NetScaler Gateway (13.1-FIPS) >= 13.1-37.241
NetScaler ADC\NetScaler Gateway (13.1-NDcPP) >= 13.1-37.241
NetScaler ADC\NetScaler Gateway (12.1-FIPS) >= 12.1-55.330
NetScaler ADC\NetScaler Gateway (12.1-NDcPP) >= 12.1-55.330
NetScaler ADC / Gateway 12.1 ͨË×°æÓë 13.0 ȫϵÁÐÒѵִïÉúÃüÖÜÆÚÖÕÖ¹£¨EOL£©£¬£¬ £¬£¬£¬£¬²»ÔÙÌṩÇå¾²²¹¶¡£¬£¬ £¬£¬£¬£¬½¨ÒéÖ±½ÓÉý¼¶ÖÁÊÜÖ§³ÖµÄÇå¾²°æ±¾£¬£¬ £¬£¬£¬£¬²¢ÓÅÏÈ˼Á¿Éý¼¶µ½ 14.1 ϵÁм°ÒÔÉϰ汾£¬£¬ £¬£¬£¬£¬ÒÔ»ñµÃºã¾ÃÖ§³ÖºÍ×îÐÂÇå¾²ÐÞ¸´ ¡£¡£¡£¡£¡£


3.2 ÔÝʱ²½·¥


ÖÎÀíÔ±¿Éͨ¹ýÔÚ NetScaler ÉèÖÃÖÐËÑË÷ÒÔÏÂÏÂÁ£¬ £¬£¬£¬£¬È·ÈÏ×°±¸ÊÇ·ñ´¦ÓÚÊÜÓ°Ïì״̬£º
¼ì²é AAA ÐéÄâЧÀÍÆ÷£¨Auth Server£©
show run | grep "add authentication vserver"
Èô·¢Ã÷ÉèÖÃÁË AAA ÐéÄâЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬ÇÒÄ¿½ñδʹÓ㬣¬ £¬£¬£¬£¬½¨ÒéÔÝʱ½ûÓà ¡£¡£¡£¡£¡£
¼ì²é Gateway£¨VPN / ICA Proxy / CVPN / RDP Proxy£©
show run | grep "add vpn vserver"
ÈçδʹÓà VPN ¹¦Ð§£¬£¬ £¬£¬£¬£¬½¨ÒéÔÝʱ¹Ø±ÕÏà¹ØÐéÄâЧÀÍÆ÷»òÏÞÖÆ»á¼û ¡£¡£¡£¡£¡£
¼ì²é¸ºÔØÆ½ºâ£¨LB£©ÐéÄâЧÀÍÆ÷°ó¶¨ IPv6 ЧÀÍ
show run | grep "add lb vserver"
show run | grep "add serviceGroup"
show run | grep "add server"
ÖØµãÅŲé HTTP¡¢SSL¡¢HTTP_QUIC ÀàÐ굀 LB ÐéÄâЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬Èô°ó¶¨ IPv6 ЧÀÍ»ò IPv6 ЧÀÍ×飬£¬ £¬£¬£¬£¬±£´æÊܹ¥»÷Σº¦ ¡£¡£¡£¡£¡£
¼ì²é°ó¶¨ DBS IPv6 ЧÀÍ»òЧÀÍÆ÷
show run | grep "add server .* -queryType AAAA"
show run | grep "bind servicegroup"
Èç²»ÐèÒª IPv6 DBS ÆÊÎöЧÀÍ£¬£¬ £¬£¬£¬£¬½¨ÒéÁ¬Ã¦½â°ó»ò½ûÓà ¡£¡£¡£¡£¡£
¼ì²é CR ÐéÄâЧÀÍÆ÷£¨HDX ÀàÐÍ£©
show run | grep "add cr vserver"
ÈôδʹÓà HDX ÀàÐÍ CR ÐéÄâЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬¿ÉÔÝʱ½ûÓà ¡£¡£¡£¡£¡£
¹ØÓÚδʹÓÃµÄ AAA¡¢VPN¡¢ICA Proxy¡¢CVPN¡¢RDP Proxy¡¢HDX ÀàÐÍ CR ÐéÄâЧÀÍÆ÷µÈ¸ßΣº¦ÉèÖ㬣¬ £¬£¬£¬£¬½¨ÒéÁ¬Ã¦½ûÓãº
disable vpn vserver
disable authentication vserver
disable cr vserver
½â°ó»ò½ûÓà IPv6 ЧÀÍ
ÈôÓªÒµÔÊÐí£¬£¬ £¬£¬£¬£¬¿ÉÔÚÊÜÓ°ÏìµÄ LB ÐéÄâЧÀÍÆ÷ÉϽâ°ó IPv6 ЧÀÍ»ò¹Ø±Õ IPv6 ¹¦Ð§£º
unbind serviceGroup
set ns param -ipv6 DISABLED
ÏÞÖÆÍⲿ»á¼û
ÔÚ·À»ðǽ¡¢WAF »ò ACL ÖÐÏÞÖÆ¶ÔÊÜÓ°Ïì×°±¸µÄ¹«Íø»á¼û£¬£¬ £¬£¬£¬£¬½öÔÊÔÊÐíÐÅÖÎÀí IP ¶Î ¡£¡£¡£¡£¡£
½¨ÒéÓÅÏÈͨ¹ýÄÚÍø»ò VPN Ç徲ͨµÀÖÎÀí×°±¸ ¡£¡£¡£¡£¡£
ÆôÓÃÇå¾²ÈÕÖ¾¼à¿Ø
¿ªÆô NetScaler Çå¾²ÈÕÖ¾¹¦Ð§£¬£¬ £¬£¬£¬£¬Öصã¼à¿ØÒì³£ÇëÇó¡¢IPv6 °ó¶¨Å²ÓõȿÉÒÉÐÐΪ ¡£¡£¡£¡£¡£
ÅäºÏ SIEM / IDS / NDR ¹¤¾ß£¬£¬ £¬£¬£¬£¬ÊµÊ±¼ì²âDZÔÚ¹¥»÷¼£Ïó ¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ ¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938/
https://nvd.nist.gov/vuln/detail/CVE-2025-7775