CVE-2023-24492
published 2023-07-11CVE-2023-24492: A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.88%
54.9th percentile
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adc | — | — |
| citrix | citrix_gateway | — | — |
| citrix | citrix_secure_access_client_for_ubuntu | < 23.5.2 | 23.5.2 |
| citrix | secure_access_client | < 23.5.2 | 23.5.2 |
| citrix | xenserver | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Citrix Secure Access client for Ubuntu Security Bulletin for CVE-2023-24492
vendor_citrix·2023-07-11·CVSS 8.8
CVE-2023-24492 [HIGH] CWE-94 Citrix Secure Access client for Ubuntu Security Bulletin for CVE-2023-24492
Citrix Secure Access client for Ubuntu Security Bulletin for CVE-2023-24492
Pre-requisites CWE CVE-2023-24492 Citrix ADC Remote Code Execution A victim user must open an attacker-crafted link and accept further prompts CWE-94 Instructions This issue has been addressed in the following versions of Citrix Secure Access client for Ubuntu: 23.5.2 and later releases Citrix recommends that customers who are affected by the above vulnerability upgrade the Citrix Secure Access client for Ubuntu installed on their endpoints by taking the following actions as soon as possible: If Citrix Secure Access client for Ubuntu is distributed via the SSL VPN upgrade control feature of Citrix ADC or Citrix Gateway: Check the versions of Citrix Secure Access client for Ubuntu that are being distributed by each
Citrix
CVE-2023-24492:
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co
vendor_citrix·2023-07-11·CVSS 9.6
CVE-2023-24492 [CRITICAL] CWE-94 CVE-2023-24492:
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co
CVE-2023-24492:
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
GHSA
GHSA-q9w5-96vr-6gqq: A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute cod
ghsa_unreviewed·2023-07-12
CVE-2023-24492 [HIGH] CWE-94 GHSA-q9w5-96vr-6gqq: A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute cod
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published