Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
History

Fri, 20 Sep 2024 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix workspace
Dell
Dell thinos
CPEs cpe:2.3:a:citrix:workspace:23.9.0.24.4:*:*:*:*:*:*:*
cpe:2.3:o:dell:thinos:2311:*:*:*:*:*:*:*
cpe:2.3:o:dell:thinos:2402:*:*:*:*:*:*:*
Vendors & Products Citrix
Citrix workspace
Dell
Dell thinos

Tue, 10 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
Description Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2024-09-10T14:55:58.906Z

Updated: 2024-09-10T19:09:13.543Z

Reserved: 2024-08-01T07:28:53.701Z

Link: CVE-2024-42423

cve-icon Vulnrichment

Updated: 2024-09-10T19:09:08.822Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-10T15:15:17.013

Modified: 2024-09-20T19:42:20.417

Link: CVE-2024-42423

cve-icon Redhat

No data.