CVE-2024-42423
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/09/2024
Last modified:
20/09/2024
Description
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:citrix:workspace:23.9.0.24.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:thinos:2402:*:*:*:*:*:*:* | ||
| cpe:2.3:a:citrix:workspace:23.9.0.24.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:thinos:2311:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



