First published: Fri Jan 14 2011(Updated: )
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Access Gateway Plug-in | <=9.2-49.8 | |
Citrix Access Gateway Plug-in | =.8.0-m50.3 | |
Citrix Access Gateway Plug-in | =8.0-m48.7 | |
Citrix Access Gateway Plug-in | =8.0-m49.2 | |
Citrix Access Gateway Plug-in | =8.0-m59.1 | |
Citrix Access Gateway Plug-in | =8.1-69.4 | |
Citrix Access Gateway Plug-in | =9.0.71.3 | |
Citrix Access Gateway Plug-in | =9.1-104.5 | |
Citrix Access Gateway Plug-in | =4.5 | |
Citrix Access Gateway Plug-in | =4.5 | |
Citrix Access Gateway Plug-in | =4.5-hf1 | |
Citrix Access Gateway Plug-in | =4.5-hf1 | |
Citrix Access Gateway Plug-in | =4.5.5 | |
Citrix Access Gateway Plug-in | =4.5.6 | |
Citrix Access Gateway Plug-in | =4.5.7 | |
Citrix Access Gateway Plug-in | =4.6.1 | |
Citrix Access Gateway Plug-in | =4.6.2 | |
Citrix Access Gateway Plug-in | =4.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4566 is categorized as a critical vulnerability due to its potential for arbitrary command execution.
To mitigate CVE-2010-4566, it is recommended to upgrade to Citrix Access Gateway version 5.0 or later.
CVE-2010-4566 affects the NT4 authentication component and NTLM authentication component of various Citrix Access Gateway versions.
Yes, CVE-2010-4566 can be exploited remotely which increases its risk to affected systems.
Systems running Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and Standard and Advanced Editions before 5.0 are at risk from CVE-2010-4566.