Summary: Cloud Software Group has issued a security bulletin for a high-severity vulnerability (CVE-2024-12284) in its NetScaler Console and NetScaler Agent, allowing authenticated attackers to execute unauthorized commands. The vulnerability has a CVSSv4 score of 8.8 and stems from inadequate privilege management. Users are strongly urged to upgrade to the patched versions to mitigate the risk of exploitation.
Affected: NetScaler Console and NetScaler Agent
Keypoints :
- Vulnerability tracked as CVE-2024-12284 allows command execution without proper authorization.
- Impacted versions include NetScaler Console and Agent versions 14.1 before 14.1-38.53 and 13.1 before 13.1-56.18.
- No mitigation steps provided; immediate upgrade to secure builds is recommended.