CVE-2024-8534 is a high-severity memory safety vulnerability affecting Citrix NetScaler ADC and Gateway products. This flaw, rated 8.1 CVSS, can lead to memory corruption and Denial of Service under specific configurations involving Gateway VPN Vservers with RDP enabled or Auth Servers with RDP enabled. While no public exploits or KEV entries exist, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape. Organizations using affected configurations should prioritize patching to mitigate the risk of disruption.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-55.321CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 12.1, < 12.1-55.321CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* | ||
>= 12.1, < 13.1-55.34CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* | ||
>= 13.1, < 13.1-37.207CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* | ||
>= 14.1, < 14.1-29.72CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.