Skip to main content

Citrix Access Gateway Legacy Authentication Command Injection Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 16 Dec 2010 5864 Views

RISK: Medium Risk

A vulnerability has been identified in Citrix Access Gateway, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by an error in the NT4 and NTLM authentication components, which could allow an attacker to subvert the authentication process or execute arbitrary commands on the appliance with root privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • Citrix Access Gateway Enterprise Edition versions 9.x
  • Citrix Access Gateway Enterprise Edition versions 8.x
  • Citrix Access Gateway Standard Edition versions 4.x
  • Citrix Access Gateway Advanced Edition versions 4.x
  • Citrix Access Gateway VPX versions 4.x

Solutions

  • The use of the vulnerable authentication methods has been deprecated in the latest versions of Citrix Access Gateway.
    Citrix recommends that affected users migrate to another authentication method.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link