imPC@ndo IT

Tracker / CVE-2024-8535

CVE-2024-8535

High 8.1

Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources

Affected products and versions

citrix netscaler_application_delivery_controller · 12.1 → 12.1-55.321
citrix netscaler_application_delivery_controller · 12.1 → 13.1-55.34
citrix netscaler_application_delivery_controller · 13.1 → 13.1-37.207
citrix netscaler_application_delivery_controller · 14.1 → 14.1-29.72
citrix netscaler_gateway · 12.1 → 13.1-55.34
citrix netscaler_gateway · 14.1 → 14.1-29.72

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References