Citrix Systems Citrix Gateway(Citrix Systems NetScaler Gateway)和Citrix ADC都是美国思杰系统(Citrix Systems)公司的产品。Citrix Gateway是一套安全的远程接入解决方案。该产品可为管理员提供应用级和数据级管控功能,以实现用户从任何地点远程访问应用和数据。Citrix ADC是一个最全面的应用程序交付和负载平衡解决方案。用于实现应用程序安全性、整体可见性和可用性。 Citrix ADC 和 Citrix Gate
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Citrix | Citrix ADC and Citrix Gateway | 13.1 ~ 13.1-45.61 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2023-24488 PoC | https://github.com/SirBugs/CVE-2023-24488-PoC | POC Details |
| 2 | CVE-2023-24488.rb The provided script is a Ruby script used to check and detect the CVE-2023-24488 security vulnerability in Citrix Gateway and Citrix ADC. | https://github.com/Abo5/CVE-2023-24488 | POC Details |
| 3 | POC for CVE-2023-24488 | https://github.com/securitycipher/CVE-2023-24488 | POC Details |
| 4 | Detect CVE-2023-24488 Exploitation Attempts | https://github.com/NSTCyber/CVE-2023-24488-SIEM-Sigma-Rule | POC Details |
| 5 | Tools to perform exploit CVE-2023-24488 | https://github.com/lazysec0x21/CVE-2023-24488 | POC Details |
| 6 | Tools to perform exploit CVE-2023-24488 | https://github.com/raytheon0x21/CVE-2023-24488 | POC Details |
| 7 | Citrix ADC and Citrix Gateway versions before 13.1 and 13.1-45.61, 13.0 and 13.0-90.11, 12.1 and 12.1-65.35 contain a cross-site scripting vulnerability due to improper input validation. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24488.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-24489 | 9.8 CRITICAL | Citrix Systems Content Collaboration 安全漏洞 |
| CVE-2023-24487 | 6.3 MEDIUM | Arbitrary file read |
| CVE-2023-24490 | 6.3 MEDIUM | Users with only access to launch VDA applications can launch an unauthorized desktop |
| CVE-2023-24486 | Local user access to a system where another user is utilizing a vulnerable version of Citr |
No comments yet