Description
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39615 | Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering. |
References
History
Fri, 20 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Citrix
Citrix workspace Dell Dell thinos |
|
| CPEs | cpe:2.3:a:citrix:workspace:23.9.0.24.4:*:*:*:*:*:*:* cpe:2.3:o:dell:thinos:2311:*:*:*:*:*:*:* cpe:2.3:o:dell:thinos:2402:*:*:*:*:*:*:* |
|
| Vendors & Products |
Citrix
Citrix workspace Dell Dell thinos |
Tue, 10 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-10T19:09:13.543Z
Reserved: 2024-08-01T07:28:53.701Z
Link: CVE-2024-42423
Updated: 2024-09-10T19:09:08.822Z
Status : Analyzed
Published: 2024-09-10T15:15:17.013
Modified: 2024-09-20T19:42:20.417
Link: CVE-2024-42423
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD