CVE-2024-8535: Authenticated user can access unintended user capabilities
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8535?
CVE-2024-8535 is considered a high-severity vulnerability due to its potential for unauthorized access to user capabilities.
How do I fix CVE-2024-8535?
Fixing CVE-2024-8535 involves applying the latest security patches provided by Citrix for the affected NetScaler ADC and NetScaler Gateway products.
Who is affected by CVE-2024-8535?
CVE-2024-8535 affects users of Citrix NetScaler ADC and Citrix NetScaler Gateway configured for Kerberos SSO.
What types of configurations are vulnerable in CVE-2024-8535?
CVE-2024-8535 is vulnerable in configurations where the appliance is set as a Gateway with KCDAccount for Kerberos SSO.
What are the potential impacts of CVE-2024-8535?
The potential impacts of CVE-2024-8535 include unauthorized access to backend resources and exposure of sensitive user capabilities.