CVE-2024-12284 in NetScaler Console Exposes Systems to Unauthorized Command Execution

CVE-2024-12284 in NetScaler Console Exposes Systems to Unauthorized Command Execution
Summary: Cloud Software Group has issued a security bulletin for a high-severity vulnerability (CVE-2024-12284) in its NetScaler Console and NetScaler Agent, allowing authenticated attackers to execute unauthorized commands. The vulnerability has a CVSSv4 score of 8.8 and stems from inadequate privilege management. Users are strongly urged to upgrade to the patched versions to mitigate the risk of exploitation.

Affected: NetScaler Console and NetScaler Agent

Keypoints :

  • Vulnerability tracked as CVE-2024-12284 allows command execution without proper authorization.
  • Impacted versions include NetScaler Console and Agent versions 14.1 before 14.1-38.53 and 13.1 before 13.1-56.18.
  • No mitigation steps provided; immediate upgrade to secure builds is recommended.

Source: https://securityonline.info/cve-2024-12284-in-netscaler-console-exposes-systems-to-unauthorized-command-execution/