漏洞分享 - Citrix 產品存在多個漏洞
Citrix 產品存在多個漏洞
一、摘要
Citrix 產品存在多個漏洞,允許遠端攻擊者利用這些漏洞,於目標系統觸發洩露敏感資料、權限提升、阻斷服務狀況及遠端執行任意程式碼。
二、存在風險
Citrix 產品存在多個漏洞,允許遠端攻擊者利用這些漏洞,於目標系統觸發洩露敏感資料、權限提升、阻斷服務狀況及遠端執行任意程式碼,其影響系統或版本如下:
- 受影響之系統/漏洞描述:
- NetScaler Console, Agent and SDX (SVM) Security Bulletin for CVE-2024-6235 and CVE-2024-6236
- CVE編號:CVE-2024-6235、CVE-2024-6236
- 影響系統/版本:
- NetScaler Console 14.1 before 14.1-25.53(CVE-2024-6235)
- NetScaler Console 14.1 before 14.1-25.53(CVE-2024-6236)
- NetScaler Console 13.1 before 13.1-53.22(CVE-2024-6236)
- NetScaler Console 13.0 before 13.0-92.31(CVE-2024-6236)
- NetScaler SDX (SVM) 14.1 before 14.1-25.53(CVE-2024-6236)
- NetScaler SDX (SVM) 13.1 before 13.1-53.17(CVE-2024-6236)
- NetScaler SDX (SVM) 13.0 before 13.0-92.31(CVE-2024-6236)
- NetScaler Agent 14.1 before 14.1-25.53(CVE-2024-6236)
- NetScaler Agent 13.1 before 13.1-53.22(CVE-2024-6236)
- NetScaler Agent 13.0 before 13.0-92.31(CVE-2024-6236)
- NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2024-5491 and CVE-2024-5492
- CVE編號:CVE-2024-5491、CVE-2024-5492
- 影響系統/版本:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-25.53
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-53.17
- NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.31
- NetScaler ADC 13.1-FIPS before 13.1-37.183
- NetScaler ADC 12.1-FIPS before 12.1-55.304
- NetScaler ADC 12.1-NDcPP before 12.1-55.304
- Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-6151
- CVE編號:CVE-2024-6151
- 影響系統/版本:
- Citrix Virtual Apps and Desktops versions before 2402
- Citrix Virtual Apps and Desktops 1912 LTSR before CU9
- Citrix Virtual Apps and Desktops 2203 LTSR before CU5
- Cloud Software Group Security Advisory for CVE-2024-6387
- CVE編號:CVE-2024-6387
- 影響系統/版本:
- Citrix Virtual Apps and Desktops 2402 之前的版本
- Citrix Virtual Apps and Desktops 1912 LTSR CU9 之前的版本
- Citrix Virtual Apps and Desktops 2203 LTSR CU5 之前的版本
- 註:已終止生命週期 (EOL)的NetScaler ADC and NetScaler Gateway 版本 12.1,受此次漏洞影響。
三、建議改善措施:
企業及使用者如有上述漏洞版本應儘速更新:
- 漏洞:NetScaler Console, Agent and SDX (SVM) Security Bulletin for CVE-2024-6235 and CVE-2024-6236
- 請更新至NetScaler Console 14.1-25.53 或 later releases of 14.1
- 請更新至NetScaler Console 13.1-53.22 或 later releases of 13.1
- 請更新至NetScaler Console 13.0-92.31 或 later releases of 13.0
- 請更新至NetScaler SDX (SVM) 14.1-25.53 或 later releases of 14.1
- 請更新至NetScaler SDX (SVM) 13.1-53.17 或 later releases of 13.1
- 請更新至NetScaler SDX (SVM) 13.0-92.31 或 later releases of 13.0
- 請更新至NetScaler Agent 14.1-25.53 或 later releases of 14.1
- 請更新至NetScaler Agent 13.1-53.22 或 later releases of 13.1
- 請更新至NetScaler Agent 13.0-92.31 或 later releases of 13.0
- 漏洞:NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2024-5491 and CVE-2024-5492
- 請更新至NetScaler ADC and NetScaler Gateway 14.1-25.53 或 later releases
- 請更新至NetScaler ADC and NetScaler Gateway 13.1-53.17 或 later releases of 13.1
- 請更新至NetScaler ADC and NetScaler Gateway 13.0-92.31 或 later releases of 13.0
- 請更新至NetScaler ADC 13.1-FIPS 13.1-37.183 或 later releases of 13.1-FIPS
- 請更新至NetScaler ADC 12.1-FIPS 12.1-55.304 或 later releases of 12.1-FIPS
- 請更新至NetScaler ADC 12.1-NDcPP 12.1-55.304 或 later releases of 12.1-NDcPP
- 漏洞:Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-6151
- 請更新至Citrix Virtual Apps and Desktops 2402 或 later versions
- 請更新至Citrix Virtual Apps and Desktops 1912 LTSR CU9 或 later cumulative updates
- 請更新至Citrix Virtual Apps and Desktops 2203 LTSR CU5 或 later cumulative updates
- 請更新至Citrix Virtual Apps and Desktops 2402 LTSR
情資報告連結:
- https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-svm-security-bulletin-for-cve20246235-and-cve20246236
- https://support.citrix.com/article/CTX677944/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20245491-and-cve20245492
- https://support.citrix.com/article/CTX678035/windows-virtual-delivery-agent-for-cvad-and-citrix-daas-security-bulletin-cve20246151
- https://support.citrix.com/article/CTX678072/cloud-software-group-security-advisory-for-cve20246387