CVE Tools

CVE-2024-5661

Potential Denial of Service affecting XenServer and Citrix Hypervisor

Published: Jun 13, 2024Updated: Nov 21, 2024 Sources: CVE List NVD BDUNVD-CWE-Other
6.0CVSSMEDIUM

Description

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.

CVSS Vector Breakdown

AV:LAC:LPR:HUI:NS:CC:NI:NA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:NConfidentiality
None
I:NIntegrity
None
A:HAvailability
High

Weaknesses

Affected Products

citrixcommercialUSCloud & SaaSaka xenserver, netscaler gateway firmware, application delivery controller firmware
citrix systems inc.commercialUSCloud & SaaSaka citrix adc, netscaler gateway, citrix gateway
the linux foundationoss-projectUSCloud & SaaSaka linuxfoundation.org, linux foundation
and 2 more affected products View all →

Exploitability

Official Patch Available

References

and 1 more references View all →

Timeline

Published
Jun 13, 2024
Last Updated
Nov 21, 2024

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2024-5661 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows