First published: Tue Sep 10 2024(Updated: )
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Citrix Workspace app | =23.9.0.24.4 | |
Dell Wyse ThinOS | =2402 | |
All of | ||
Citrix Workspace app | =23.9.0.24.4 | |
Dell Wyse ThinOS | =2311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42423 has been classified as a medium severity vulnerability due to its potential impact on system security.
To remediate CVE-2024-42423, update Citrix Workspace App to version 23.9.0.24.5 or later, and ensure all patches are applied.
CVE-2024-42423 affects users operating Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311.
CVE-2024-42423 is identified as an Incorrect Authorization vulnerability that allows unauthorized actions by local low-privileged users.
No, CVE-2024-42423 requires local access, as it can only be exploited by unauthenticated users on the affected system.