CVE-2024-8535
Published: Nov 12, 2024
Modified: Nov 21, 2024
Description
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources
| Vendor | Product | Versions |
|---|---|---|
NetScaler | NetScaler ADC | affected 14.1 - < 29.72affected 13.1 - < 55.34affected 13.1 FIPS - < 37.207affected 12.1-FIPS - < 55.321affected 12.1-NDcPP - < 55.321 |
NetScaler | NetScaler Gateway | affected 14.1 - < 29.72affected 13.1 - < 55.34affected 13.1-FIPS - < 37.207affected 12.1-FIPS - < 55.321affected 12.1-NDcPP - < 55.321 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now