CVE-2023-24488 is a cross-site scripting (XSS) vulnerability affecting Citrix ADC and Citrix Gateway, allowing an attacker to inject malicious scripts into web pages viewed by other users. With a CVSS score of 6.1 (Medium), this vulnerability has a low attack complexity and requires user interaction, potentially leading to limited impact on confidentiality and integrity. While not currently listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 99/100 indicate a high probability of exploitation, and Nuclei templates for detection are available. Community discussion and media coverage suggest moderate attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-65.35CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.0-90.11CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 13.1, < 13.1-45.61CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 12.1, < 12.1-55.296CPE matchmatch criteria | cpe:2.3:a:citrix:application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 12.1, < 12.1-55.296CPE matchmatch criteria | cpe:2.3:a:citrix:application_delivery_controller:*:*:*:*:ndcpp:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.