Record summary

CVE-2024-6235 has a selected CVSS score of 9.4 (critical); EIP currently links 1 Nuclei template.

Description

Sensitive information disclosure in NetScaler Console

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 17, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

NetScaler ADC and NetScaler Gateway

Browse Citrix / NetScaler ADC and NetScaler Gateway
VulnCheckVersion data not supplied

Default status: unaffected

CVE List14.1 to < 25.53affected

Default status: unaffected

CVE List14.1 to < 25.53affected

Nuclei templates

1
ProjectDiscoveryCRITICALNetScaler Console - Sensitive Information DisclosureCVSS 8.8

Sensitive information disclosure in NetScaler Console

Impact

Attackers can access sensitive information including session secrets and administrative credentials from the NetScaler Console without proper authentication.

Remediation

Apply the patches specified in Citrix advisory CTX677998 to address the information disclosure vulnerability in NetScaler Console.

WeaknessesCWE-287
AuthorsDhiyaneshDk
Template tagscvecve2024netscalerexposurevkevvuln
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:citrix:netscaler_console:*:*:*:*:*:*:*:*
Shodan: title:"NetScaler Gateway"

Source: ProjectDiscovery

References

2