PT-2024-29938 · Citrix+1 · Citrix Workspace App+1

Published

2024-09-10

·

Updated

2024-09-20

·

CVE-2024-42423

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311
Description The issue is related to an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions, leading to information disclosure and tampering.
Recommendations For Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311, consider disabling Citrix CEB for WebLogin as a temporary workaround to minimize the risk of exploitation. Restrict access to sensitive information and implement additional controls to prevent unauthorized actions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-42423

Affected Products

Citrix Workspace App
Dell Thinos