PT-2024-5023 · Citrix · Citrix Netscaler Console
Published
2024-07-09
·
Updated
2025-06-21
·
CVE-2024-6235
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Citrix NetScaler Console (affected versions not specified)
Description
The issue is related to sensitive information disclosure in the NetScaler Console due to improper authentication. This allows an unauthenticated attacker to obtain an admin-level session ID from an internal API and use it to create other admin users on the system. The vulnerability can be exploited by an attacker with network access to the management interface, enabling them to access sensitive information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Netscaler Console