CyberzSOC

Publication detail
← Back to advisories & guidance

Citrix Releases Security Updates for Multiple Products ↗ source

July 9, 2024 CISA Alert

Summary

A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. NetScaler ADC and NetScaler Gateway Security Update for CVE-2024-5491 and CVE-2024-5492 NetScaler Console, Agent and SVM Security Update for CVE-2024-6235 and CVE-2024-6236 Citrix Workspace app for HTML5 Security Bulletin CVE-2024-6148 and CVE-2024-6149 Citrix Provisioning Security Bulletin CVE-2024-6150 Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-6151 Citrix Workspace app for Windows Security Bulletin CVE-2024-6286 This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-6235 9.4 Critical NetScaler NetScaler Console Sensitive information disclosure in NetScaler Console
CVE-2024-6151 8.5 High Citrix Windows Virtual Delivery Agent Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps a…
CVE-2024-6286 8.5 High Citrix Citrix Workspace app for Windows Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-5491 7.2 High NetScaler NetScaler ADC Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
CVE-2024-6236 7.1 High NetSclaer NetScaler Console Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
CVE-2024-6148 5.3 Medium Citrix Citrix Workspace app for HTML5 Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
CVE-2024-5492 5.1 Medium NetSclaer NetScaler ADC Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
CVE-2024-6149 4.8 Medium Citrix Citrix Workspace app for HTML5 Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
CVE-2024-6150 4.8 Medium Citrix Citrix Provisioning A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.