{"short":"Citrix Workspace App contains vulnerability"}
CVE-2024-42423

7.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
10 September 2024

Summary

Citrix Workspace App version 23.9.0.24.4, when used on Dell ThinOS 2311, is impacted by an Incorrect Authorization vulnerability. This issue arises specifically when Citrix CEB is enabled for WebLogin. It allows local unauthenticated users with minimal privileges to exploit this vulnerability. Consequently, they may bypass existing security measures, leading to unauthorized actions such as information disclosure and tampering with system operations. The consequences of this vulnerability necessitate prompt attention and remediation to safeguard sensitive data and maintain system integrity.

Affected Version(s)

Wyse Proprietary OS (Modern ThinOS) ThinOS 2311

Wyse Proprietary OS (Modern ThinOS) ThinOS 2402

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.