{"short":"Citrix Workspace App contains vulnerability"}
CVE-2024-42423
7.1HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 10 September 2024
Summary
Citrix Workspace App version 23.9.0.24.4, when used on Dell ThinOS 2311, is impacted by an Incorrect Authorization vulnerability. This issue arises specifically when Citrix CEB is enabled for WebLogin. It allows local unauthenticated users with minimal privileges to exploit this vulnerability. Consequently, they may bypass existing security measures, leading to unauthorized actions such as information disclosure and tampering with system operations. The consequences of this vulnerability necessitate prompt attention and remediation to safeguard sensitive data and maintain system integrity.
Affected Version(s)
Wyse Proprietary OS (Modern ThinOS) ThinOS 2311
Wyse Proprietary OS (Modern ThinOS) ThinOS 2402
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved