Advisory 64: Citrix Releases Security Updates for Multiple Products
Release Date: 09th of July 2024
Impact : HIGH / CRITICAL
TLP Rating: Clear
CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.
What is it?
Citrix has released security updates for several of its products to address multiple vulnerabilities. These updates are crucial for maintaining the security and integrity of systems using Citrix software.
What are the Systems affected?
The following Citrix products are affected;
- NetScaler ADC and NetScaler Gateway Security Update for CVE-2024-5491 and CVE-2024-5492
- NetScaler Console, Agent and SVM Security Update for CVE-2024-6235 and CVE-2024-62336
- Citrix Workspace app for HTML5 Security Bulletin CVE-2024-6148 and CVE-2024-6149
- Citrix Provisioning Security Bulletin CVE-2024-6150
- Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-6151
- Citrix Workspace app for Windows Security Bulletin CVE-2024-6286
What this means?
If Vulnerabilities are not addressed, a cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.
Mitigation process
CERTVU Encourages users and administrators to review the below and apply necessary security updates for the specific Citrix and upgrade to supported versions that address the vulnerabilities.
References
- https://www.cisa.gov/news-events/alerts/2024/07/09/citrix-releases-security-updates-multiple-products
- https://support.citrix.com/article/CTX677944/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20245491-and-cve20245492
- https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-svm-security-bulletin-for-cve20246235-and-cve20246236
- https://support.citrix.com/article/CTX678037/citrix-workspace-app-for-html5-security-bulletin-cve20246148-and-cve20246149
- https://support.citrix.com/article/CTX678025/citrix-provisioning-security-bulletin-cve20246150
- https://support.citrix.com/article/CTX678035/windows-virtual-delivery-agent-for-cvad-and-citrix-daas-security-bulletin-cve20246151
- https://support.citrix.com/article/CTX678036/citrix-workspace-app-for-windows-security-bulletin-cve20246286
- Download advisory (English): Citrix Releases Security Updates for Multiple Products
- Download advisory (Bislama): Citrix i Rilisim olgeta Sekuriti Apdeit blong Plante Prodak
- Download advisory (French): Citrix publie des mises à jour de sécurité pour plusieurs produits