vendor:
Access Gateway
by:
George D. Gal
7,5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Access Gateway
Affected Version From: Access Gateway Enterprise Edition (up to 9.2-49.8)
Affected Version To: Access Gateway Standard & Advanced Edition (prior to 5.0)
Patch Exists: YES
Related CWE: CVE-2010-4566
CPE: a:citrix:access_gateway
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Citrix Access Gateway Command Injection Vulnerability
On August 2nd, VSR identified a vulnerability in Citrix Access Gateway within the way user authentication credentials are handled. Under certain configuration settings it appears that user credentials are passed as arguments to a command line program to authenticate the user. A lack of data validation and the mechanism in which the external program is spawned results in the potential for command injection and arbitrary command execution on the Access Gateway.
Mitigation:
Updated Software Released, NT4 Authentication Removed