CVE-2024-8535
12.11.2024, 19:15
Authenticated user can access unintended user capabilitiesinNetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resourcesORthe appliance must be configured as anAuth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resourcesEnginsight
Vendor | Product | Version |
---|---|---|
citrix | netscaler_application_delivery_controller | 12.1 ≤ 𝑥 < 12.1-55.321 |
citrix | netscaler_application_delivery_controller | 12.1 ≤ 𝑥 < 12.1-55.321 |
citrix | netscaler_application_delivery_controller | 12.1 ≤ 𝑥 < 13.1-55.34 |
citrix | netscaler_application_delivery_controller | 13.1 ≤ 𝑥 < 13.1-37.207 |
citrix | netscaler_application_delivery_controller | 14.1 ≤ 𝑥 < 14.1-29.72 |
citrix | netscaler_gateway | 12.1 ≤ 𝑥 < 13.1-55.34 |
citrix | netscaler_gateway | 14.1 ≤ 𝑥 < 14.1-29.72 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration