Citrix has warned users about severe vulnerabilities in their widely-used NetScaler products. These vulnerabilities, known as CVE-2024-6235 and CVE-2024-6236, could potentially allow unauthorized access to sensitive information and cause denial-of-service (DoS) attacks.
CVE-2024-6235: Sensitive Information Disclosure (Critical Severity)
By infosecbulletin
/ Tuesday , December 3 2024
Cisco has released an updated security advisory about CVE-2014-2120, a vulnerability in the WebVPN login page of Cisco Adaptive Security...
Read More
By infosecbulletin
/ Tuesday , December 3 2024
A serious zero-day vulnerability has been found in TP-Link Archer, Deco, and Tapo routers, which could let attackers inject harmful...
Read More
By infosecbulletin
/ Monday , December 2 2024
IBM revealed several critical vulnerabilities in its Security Verify Access Appliance, which could pose serious security risks to users identified...
Read More
By infosecbulletin
/ Monday , December 2 2024
Cybersecurity researchers are alerting users about phishing email campaigns using a toolkit called "Rockstar 2FA" to steal Microsoft 365 account...
Read More
By infosecbulletin
/ Sunday , December 1 2024
A workshop on "DDoS use cases & solutions for government & BFSI" held at Bangladesh computer society premises on Saturday...
Read More
By infosecbulletin
/ Saturday , November 30 2024
Uganda’s finance ministry confirmed media reports that hackers breached the central bank’s systems and stole money, but refuted the claims...
Read More
By infosecbulletin
/ Friday , November 29 2024
CERT Germany and Zyxel have alerted about a serious vulnerability in Zyxel firewalls, identified as CVE-2024-11667. This flaw is being...
Read More
By infosecbulletin
/ Friday , November 29 2024
Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
By infosecbulletin
/ Thursday , November 28 2024
CERT-In has flagged a security vulnerability in Oracle’s Agile Product Lifecycle Management (PLM) software, identified as CVE-2024-21287 and cataloged as...
Read More
By infosecbulletin
/ Thursday , November 28 2024
On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, Microsoft Copilot Studio and Azure...
Read More
The flaw in the NetScaler Console (previously known as NetScaler ADM) is rated with a CVSSv4 score of 9.4. It could let attackers access confidential data without authorization, possibly exposing trade secrets, customer information, or other important assets.
CVE-2024-6236: Denial of Service (High Severity)
This vulnerability, rated with a score of 7.1, affects NetScaler Console, NetScaler SVM, and NetScaler Agent. Attackers exploiting this flaw could disrupt the normal operation of NetScaler services, causing downtime and financial losses for affected organizations.
Affected Versions and Urgent Call to Action:
NetScaler Console, SVM, and Agent have security vulnerabilities. Cloud Software Group advises users to update their NetScaler software to the latest patched versions as soon as possible.
The specific patched versions for each product are:
NetScaler Console: 14.1-25.53 or later for 14.1, 13.1-53.22 or later for 13.1, and 13.0-92.31 or later for 13.0
NetScaler SVM: 14.1-25.53 or later for 14.1, 13.1-53.17 or later for 13.1, and 13.0-92.31 or later for 13.0
NetScaler Agent: 14.1-25.53 or later for 14.1, 13.1-53.22 or later for 13.1, and 13.0-92.31 or later for 13.0
Citrix has warned users about two security vulnerabilities (CVE-2024-6286 and CVE-2024-6151) in the Citrix Workspace app for Windows and the Virtual Delivery Agent for Windows. Both vulnerabilities have a high severity CVSSv4 score of 8.5.