CVE-2024-6236
published 2024-07-10CVE-2024-6236: Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
PriorityP334high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.74%
50.5th percentile
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | netscaler_agent | — | — |
| citrix | netscaler_agent | >= 13.0-58.30 < 13.0-92.31 | 13.0-92.31 |
| citrix | netscaler_agent | >= 13.1-4.43 < 13.1-53.22 | 13.1-53.22 |
| citrix | netscaler_agent | >= 14.1-4.42 < 14.1-25.53 | 14.1-25.53 |
| citrix | netscaler_console | — | — |
| citrix | netscaler_console | >= 13.0-58.30 < 13.0-92.31 | 13.0-92.31 |
| citrix | netscaler_console | >= 13.1-4.43 < 13.1-53.22 | 13.1-53.22 |
| citrix | netscaler_console | >= 14.1-4.42 < 14.1-25.53 | 14.1-25.53 |
| citrix | netscaler_sdx | — | — |
| citrix | netscaler_sdx | >= 13.0-91.12 < 13.0-92.31 | 13.0-92.31 |
| citrix | netscaler_sdx | >= 13.1-49.13 < 13.1-53.17 | 13.1-53.17 |
| citrix | netscaler_sdx | >= 14.1-4.42 < 14.1-25.53 | 14.1-25.53 |
| citrix | netscaler_svm | — | — |
| citrix | xenserver | — | — |
| netscaler | agent | >= 13.0 < 92.31 | 92.31 |
| netscaler | agent | >= 13.1 < 52.25 | 52.25 |
| netscaler | agent | >= 14.1 < 25.53 | 25.53 |
| netscaler | sdx | >= 13.0 < 92.31 | 92.31 |
| netscaler | sdx | >= 13.1 < 52.25 | 52.25 |
| netscaler | sdx | >= 14.1 < 25.53 | 25.53 |
| netsclaer | netscaler_console | >= 13.0 < 92.31 | 92.31 |
| netsclaer | netscaler_console | >= 13.1 < 52.25 | 52.25 |
| netsclaer | netscaler_console | >= 14.1 < 25.53 | 25.53 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation FactoryTalk System Services and Policy Manager
cisa_ics·2024-07-11·CVSS 6.0
[MEDIUM] Rockwell Automation FactoryTalk System Services and Policy Manager
ICS Advisory
##
Rockwell Automation FactoryTalk System Services and Policy Manager
Release DateJuly 11, 2024
Alert CodeICSA-24-193-19
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.0
- ATTENTION: Low attack complexity
- Vendor: Rockwell Automation
- Equipment: FactoryTalk System Services and Policy Manager
- Vulnerabilities: Improper Privilege Management
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to obtain private keys, which would result in impersonating resources on the secured network.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Rockwell Automation FactoryTalk products are affected:
- FactoryT
Citrix
NetScaler Console, Agent and SDX (SVM) Security Bulletin for CVE-2024-6235 and CVE-2024-6236
vendor_citrix·2024-07-10·CVSS 9.4
CVE-2024-6235 [CRITICAL] CWE-119 NetScaler Console, Agent and SDX (SVM) Security Bulletin for CVE-2024-6235 and CVE-2024-6236
NetScaler Console, Agent and SDX (SVM) Security Bulletin for CVE-2024-6235 and CVE-2024-6236
of Problem Two vulnerabilities have been discovered in NetScaler Console (formerly NetScaler ADM), NetScaler SDX (SVM), and NetScaler Agent. Refer to below for further details:
CVE References: CVE-2024-6235, CVE-2024-6236
Affected Products: NetScaler Agent, NetScaler Console, NetScaler SDX, NetScaler SVM, XenServer
Severity: Critical
CVSS Score: 9.4
Remediation:
Cloud Software Group strongly urges customers of NetScaler Console to install the relevant updated versions of NetScaler Console as soon as possible: NetScaler Console 14.1-25.53 and later releases of 14.1 NetScaler Console 13.1-53.22 and later releases of 13.1 NetScaler Console 13.0-92.31 and later releases of 13.0 NetScaler SDX (SVM) 1
GHSA
GHSA-jjrp-3hrg-cj26: Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
ghsa_unreviewed·2024-07-10
CVE-2024-6236 [HIGH] CWE-119 GHSA-jjrp-3hrg-cj26: Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
No detection rules found.
No public exploits indexed.
2024-07-10
Published