PT-2024-4265 · Citrix · Xenserver+1

Published

2024-06-11

·

Updated

2024-10-28

·

CVE-2024-5661

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Citrix Hypervisor versions 8.2 CU1 LTSR XenServer version 8
Description The issue is related to improper rate limiting in an endpoint, which may allow an attacker to cause a denial of service. A malicious administrator of a guest VM can exploit this to make the host slow and/or unresponsive.
Recommendations For Citrix Hypervisor version 8.2 CU1 LTSR, update to a version that includes the fix for this issue. For XenServer version 8, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable endpoint to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-04752
CVE-2024-5661

Affected Products

Citrix Hypervisor
Xenserver