9.3

CVE-2010-4566

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

Data is provided by the National Vulnerability Database (NVD)
CitrixAccess Gateway Editionenterprise Version <= 9.2-49.8
CitrixAccess Gateway Version.8.0 Updatem50.3 Editionenterprise
CitrixAccess Gateway Version8.0 Updatem48.7 Editionenterprise
CitrixAccess Gateway Version8.0 Updatem49.2 Editionenterprise
CitrixAccess Gateway Version8.0 Updatem59.1 Editionenterprise
CitrixAccess Gateway Version8.1-69.4 Editionenterprise
CitrixAccess Gateway Version9.0.71.3 Editionenterprise
CitrixAccess Gateway Version9.1-104.5 Editionenterprise
CitrixAccess Gateway Version4.5 Editionadvanced
CitrixAccess Gateway Version4.5 Editionstandard
CitrixAccess Gateway Version4.5 Updatehf1
CitrixAccess Gateway Version4.5 Updatehf1 Editionadvanced
CitrixAccess Gateway Version4.5.5 Editionstandard
CitrixAccess Gateway Version4.5.6 Editionstandard
CitrixAccess Gateway Version4.5.7 Editionstandard
CitrixAccess Gateway Version4.6.1 Editionstandard
CitrixAccess Gateway Version4.6.2 Editionstandard
CitrixAccess Gateway Version4.6.3 Editionstandard
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 71.85% 0.986
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C