Citrix has warned users about severe vulnerabilities in their widely-used NetScaler products. These vulnerabilities, known as CVE-2024-6235 and CVE-2024-6236, could potentially allow unauthorized access to sensitive information and cause denial-of-service (DoS) attacks.
CVE-2024-6235: Sensitive Information Disclosure (Critical Severity)
By infosecbulletin
/ Friday , April 18 2025
According to Shadowserver Foundation around 17,000 Fortinet devices worldwide have been compromised using a new technique called "symlink". This number...
Read More
By infosecbulletin
/ Friday , April 18 2025
A critical security flaw has been found in the Erlang/Open Telecom Platform (OTP) SSH implementation, allowing an attacker to run...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
By infosecbulletin
/ Thursday , April 17 2025
Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Check Point Research warns of the active exploitation of a new vulnerability, CVE-2025-24054, which lets hackers leak NTLMv2-SSP hashes using...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
PwC has ceased operations in more than a dozen countries that its global bosses have deemed too small, risky or...
Read More
The flaw in the NetScaler Console (previously known as NetScaler ADM) is rated with a CVSSv4 score of 9.4. It could let attackers access confidential data without authorization, possibly exposing trade secrets, customer information, or other important assets.
CVE-2024-6236: Denial of Service (High Severity)
This vulnerability, rated with a score of 7.1, affects NetScaler Console, NetScaler SVM, and NetScaler Agent. Attackers exploiting this flaw could disrupt the normal operation of NetScaler services, causing downtime and financial losses for affected organizations.
Affected Versions and Urgent Call to Action:
NetScaler Console, SVM, and Agent have security vulnerabilities. Cloud Software Group advises users to update their NetScaler software to the latest patched versions as soon as possible.
The specific patched versions for each product are:
NetScaler Console: 14.1-25.53 or later for 14.1, 13.1-53.22 or later for 13.1, and 13.0-92.31 or later for 13.0
NetScaler SVM: 14.1-25.53 or later for 14.1, 13.1-53.17 or later for 13.1, and 13.0-92.31 or later for 13.0
NetScaler Agent: 14.1-25.53 or later for 14.1, 13.1-53.22 or later for 13.1, and 13.0-92.31 or later for 13.0
Citrix has warned users about two security vulnerabilities (CVE-2024-6286 and CVE-2024-6151) in the Citrix Workspace app for Windows and the Virtual Delivery Agent for Windows. Both vulnerabilities have a high severity CVSSv4 score of 8.5.