Citrix NetScaler ADC and NetScaler Gateway CVE-2025-5777
Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt: endpointEndpoint2025-07-17version:1
This analytic detects exploitation activity of CVE-2025-5777 using Cisco Secure Firewall Intrusion Events.
It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signature 65118 (Citrix NetScaler memory overread attempt) is triggered
If confirmed malicious, this behavior is highly indicative of a potential exploitation of CVE-2025-5777.
Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure: networkWeb Application2025-01-07version:1
This detection identifies potential exploitation attempts of CVE-2025-5777 (CitrixBleed 2), a memory disclosure vulnerability in Citrix NetScaler ADC and Gateway.
The vulnerability is triggered by sending POST requests with incomplete form data to the /p/u/doAuthentication.do endpoint, causing the device to leak memory contents including session tokens and authentication materials.
This search looks for POST requests to the vulnerable endpoint that may indicate scanning or exploitation attempts.