← Back

CVE-2024-8535

nvd nist
Published: Nov 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.8
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: secure@citrix.com (Secondary)

Description

Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources

Affected (7)

2 products
Netscaler Gateway
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Citrix
From 12.1 to 13.1-55.34
From 14.1 to 14.1-29.72
From 12.1 to 12.1-55.321
From 13.1 to 13.1-37.207
From 12.1 to 12.1-55.321
Citrix
From 12.1 to 13.1-55.34
From 14.1 to 14.1-29.72

Timeline

No history available yet.