CVE-2024-8534
Citrix NetScaler ADC and Gateway – Memory Safety Vulnerability
Description
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled
INFO
Published Date :
Nov. 12, 2024, 7:15 p.m.
Last Modified :
Nov. 21, 2024, 5:15 p.m.
Source :
[email protected]
Remotely Exploitable :
Yes !
Impact Score :
1.4
Exploitability Score :
3.9
Public PoC/Exploit Available at Github
CVE-2024-8534 has a 1 public PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
Affected Products
The following products are affected by CVE-2024-8534
vulnerability.
Even if cvefeed.io
is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
No affected product recoded yet
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2024-8534
.
URL | Resource |
---|---|
https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US |
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
A collection of Vulnerability Research and Reverse Engineering writeups.
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2024-8534
vulnerability anywhere in the article.
- Cybersecurity News
Citrix NetScaler Under Siege: Significant Increase in Brute Force Attacks Observed
A significant increase in brute-force attacks targeting outdated and misconfigured Citrix NetScaler devices has been observed in Germany, prompting warnings from cybersecurity experts and organization ... Read more
- Cybersecurity News
XorBot Botnet Resurfaces with Advanced Evasion and Exploits, Threatens IoT Devices
NSFOCUS has identified a resurgence of the XorBot botnet, a potent threat to Internet of Things (IoT) devices worldwide. First observed in late 2023, XorBot has evolved significantly, introducing adva ... Read more
- Cybersecurity News
NVIDIA Base Command Manager Update Patches CVE-2024-0138 (CVSS 9.8)
NVIDIA has issued a critical security update for its Base Command Manager software, addressing a vulnerability that could open systems to a range of serious attacks. The flaw, tracked as CVE-2024-0138 ... Read more
- TheCyberThrone
TheCyberThrone Security Weekly Review – November 16, 2024
Welcome to TheCyberThrone cybersecurity week in review will be posted covering the important security happenings. This review is for the weeks ending Saturday, November 16, 2024.GitLab fixes High seve ... Read more
- TheCyberThrone
GitLab fixes High severity vulnerability CVE-2024-9693
GitLab has released patches to address a high-severity vulnerability that could grant unauthorized access to Kubernetes clusters.The most serious vulnerability tracked as CVE-2024-9693 with a CVSS sco ... Read more
- TheCyberThrone
WordPress WPMLS Theme has a Critical Bug CVE-2024-10470
A security researcher, Friderika Baranyai, has discovered a critical path traversal bug in the WPLMS WordPress theme that leaves websites , allows attackers to read and delete arbitrary files on the s ... Read more
- TheCyberThrone
Ivanti Addressed Multiple Vulnerabilities as part of November 2024 advisories
Ivanti has released trove of security updates as part of November 2024 security advisoryIvanti Endpoint ManagerThe most critical vulnerability, CVE-2024-50330 with a CVSS score of 9.8, is a SQL injec ... Read more
- TheCyberThrone
Microsoft Patch Tuesday – November 2024
Microsoft patched 87 CVEs in its November 2024 Patch Tuesday release, with four rated critical, 82 rated important and one rated moderate.26 Elevation of Privilege vulnerabilities2 Security Feature By ... Read more
- TheCyberThrone
CISA KEV Catalog Update Part III- November 2024
The US CISA adds Microsoft, Metabase, Cisco, and Atlassian vulnerabilities to its Known Exploited Vulnerabilities Catalog based on the evidence of mass exploitation.CVE-2014-2120 Thr vulnerability wit ... Read more
- TheCyberThrone
Citrix addresses NetScaler Vulnerabilities CVE-2024-8534 and CVE-2024-8535
Citrix has warned about two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, products that provide application delivery and security services, could allow attackers to disrupt services ... Read more
- security.nl
NetScaler komt met 'kritieke beveiligingsupdates' voor ADC en Gateway
NetScaler heeft 'kritieke beveiligingsupdates' voor kwetsbaarheden in ADC en Gateway uitgebracht. ADC en Gateway versies 12.1 en 13.0 zijn end-of-life en kwetsbaar. Organisaties die van deze versies g ... Read more
The following table lists the changes that have been made to the
CVE-2024-8534
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Nov. 21, 2024
Action Type Old Value New Value Removed CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Nov. 13, 2024
Action Type Old Value New Value Added CVSS V3.1 CISA-ADP AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L -
CVE Received by [email protected]
Nov. 12, 2024
Action Type Old Value New Value Added Description Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled Added Reference Citrix Systems, Inc. https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US [No types assigned] Added CWE Citrix Systems, Inc. CWE-119 Added CVSS V4.0 Citrix Systems, Inc. CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2024-8534
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2024-8534
weaknesses.