« Volver al listado

CVE-2024-8534

Estado: AnalizadaAlta (8.4)—

Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS:4.0 con AV:N/AC:L indica explotación remota sin privilegios (T1190). La corrupción de memoria (CWE-119, CWE-787) causa DoS en NetScaler ADC/Gateway; ejecución de código remoto posible pero no explícita en la descripción.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-8534",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8534",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-13T14:38:35.887321Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "secure@citrix.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.4,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "secure@citrix.com",
      "affectedData": [
        {
          "vendor": "NetSclaer",
          "product": "NetScaler ADC",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "29.72",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1",
              "lessThan": "55.34",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1-FIPS",
              "lessThan": "37.207",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "12.1-FIPS",
              "lessThan": "55.321",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "12.1-NDcPP",
              "lessThan": "55.321",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NetScaler",
          "product": "NetScaler Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "29.72",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1",
              "lessThan": "55.34",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "13.1-FIPS",
              "lessThan": "37.207",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "12.1-FIPS",
              "lessThan": "55.321",
              "versionType": "patch"
            },
            {
              "status": "affected",
              "version": "12.1-NDcPP",
              "lessThan": "55.321",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:netscaler:adc:*:*:*:*:*:*:*:*"
          ],
          "vendor": "netscaler",
          "product": "adc",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "14.1-29.72",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:netscaler:gateway:*:*:*:*:*:*:*:*"
          ],
          "vendor": "netscaler",
          "product": "gateway",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "14.1-29.72",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netscaler:adc:*:*:*:*:*:*:*:*"
          ],
          "vendor": "netscaler",
          "product": "adc",
          "versions": [
            {
              "status": "affected",
              "version": "13.1",
              "lessThan": "13.1-55.34",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netscaler:netscaler-adc_13.1-fips:*:*:*:*:*:*:*:*"
          ],
          "vendor": "netscaler",
          "product": "netscaler-adc_13.1-fips",
          "versions": [
            {
              "status": "affected",
              "version": "13.1",
              "lessThan": "13.1-37.207",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netscaler:netscaler-adc_12.1-fips:12.1:*:*:*:*:*:*:*"
          ],
          "vendor": "netscaler",
          "product": "netscaler-adc_12.1-fips",
          "versions": [
            {
              "status": "affected",
              "version": "12.1",
              "lessThan": "12.1-55.321",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netscaler:netscaler-adc_12.1-ndcpp:12.1:*:*:*:*:*:*:*"
          ],
          "vendor": "netscaler",
          "product": "netscaler-adc_12.1-ndcpp",
          "versions": [
            {
              "status": "affected",
              "version": "12.1",
              "lessThan": "12.1-55.321",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-11-12T19:15:18.907",
  "references": [
    {
      "url": "https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@citrix.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@citrix.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled"
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de seguridad de la memoria que provoca corrupción de memoria y denegación de servicio en NetScaler ADC y Gateway si el dispositivo debe configurarse como un Gateway (VPN Vserver) con la función RDP habilitada O el dispositivo debe configurarse como un Gateway (VPN Vserver) y se crea un perfil de servidor proxy RDP y se configura como Gateway (VPN Vserver) O el dispositivo debe configurarse como un servidor de autenticación (AAA Vserver) con la función RDP habilitada"
    }
  ],
  "lastModified": "2026-06-17T08:22:48.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5EE3463-C7DB-493D-A14E-7A8891B903D9",
              "versionEndExcluding": "12.1-55.321",
              "versionStartIncluding": "12.1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EAF1004-344C-4A0A-A1B6-A8932D763724",
              "versionEndExcluding": "12.1-55.321",
              "versionStartIncluding": "12.1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F832616-B768-4B98-AF21-3C32CB1F9A3B",
              "versionEndExcluding": "13.1-55.34",
              "versionStartIncluding": "12.1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23A038D6-AA3B-4833-AEE8-0DCE05DC21E9",
              "versionEndExcluding": "13.1-37.207",
              "versionStartIncluding": "13.1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29410A07-D4E1-4D0F-BC78-4A2323325370",
              "versionEndExcluding": "14.1-29.72",
              "versionStartIncluding": "14.1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B767B864-9D9B-4C28-A216-570E8835D466",
              "versionEndExcluding": "13.1-55.34",
              "versionStartIncluding": "12.1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E814029-E1B3-48E7-847E-B5A522D06780",
              "versionEndExcluding": "14.1-29.72",
              "versionStartIncluding": "14.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@citrix.com"
}