CVE-2024-8535 - CVE House
Back to Database
Status published Medium CVE-2024-8535

Authenticated user can access unintended user capabilities

Vulnerability Description

Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8535

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

NetScaler ADC, NetScaler Gateway
Vulnerable Versions:
14.1, 13.1, 13.1 FIPS, 12.1-FIPS, 12.1-NDcPP, 13.1-FIPS

Timeline

Official Publish: November 12th, 2024
Last Modified: November 21st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.