CVE-2023-24492 is a critical remote code execution vulnerability in the Citrix Secure Access client for Ubuntu. It allows an attacker to execute arbitrary code if a user opens a malicious link and accepts subsequent prompts. With a CVSS score of 8.8 (High), exploitation requires user interaction but can lead to full compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been confirmed, the vulnerability has garnered significant community discussion and media coverage, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.5.2CPE matchmatch criteria | cpe:2.3:a:citrix:secure_access_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.