PT-2024-5023 · Citrix · Citrix Netscaler Console

Published

2024-07-09

·

Updated

2025-06-21

·

CVE-2024-6235

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Citrix NetScaler Console (affected versions not specified)
Description The issue is related to sensitive information disclosure in the NetScaler Console due to improper authentication. This allows an unauthenticated attacker to obtain an admin-level session ID from an internal API and use it to create other admin users on the system. The vulnerability can be exploited by an attacker with network access to the management interface, enabling them to access sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-05547
CVE-2024-6235

Affected Products

Citrix Netscaler Console