Citrix Access Gateway Legacy Authentication Command Injection Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
16 Dec 2010
5864
Views
RISK: Medium Risk
A vulnerability has been identified in Citrix Access Gateway, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an error in the NT4 and NTLM authentication components, which could allow an attacker to subvert the authentication process or execute arbitrary commands on the appliance with root privileges.
Impact
- Remote Code Execution
System / Technologies affected
- Citrix Access Gateway Enterprise Edition versions 9.x
- Citrix Access Gateway Enterprise Edition versions 8.x
- Citrix Access Gateway Standard Edition versions 4.x
- Citrix Access Gateway Advanced Edition versions 4.x
- Citrix Access Gateway VPX versions 4.x
Solutions
- The use of the vulnerable authentication methods has been deprecated in the latest versions of Citrix Access Gateway.
Citrix recommends that affected users migrate to another authentication method.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with