CVE-2007-4017: CSRF
Published Jul 26, 2007
·Updated
Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators.
Affected Software
2 affected components
Citrix Access Gateway=4.5
Citrix Access Gateway=4.5
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 26, 2007
CVE Published
01:30 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4017?
CVE-2007-4017 is classified as a medium severity vulnerability.
2
How do I fix CVE-2007-4017?
To mitigate CVE-2007-4017, upgrade the Citrix Access Gateway firmware to version 4.5.5 or later.
3
What types of attacks are possible with CVE-2007-4017?
CVE-2007-4017 allows remote attackers to perform unauthorized configuration changes via cross-site request forgery.
4
Which versions of Citrix Access Gateway are affected by CVE-2007-4017?
CVE-2007-4017 affects Citrix Access Gateway versions 4.5 Standard and Advanced.
5
Is user authentication impacted by CVE-2007-4017?
Yes, CVE-2007-4017 can be exploited by attackers to carry out actions as an authenticated administrator.