CVE-2007-3679
Summary
| CVE | CVE-2007-3679 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-25 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Access Gateway | All | hf1 | advanced | All |
| Application | Citrix | Access Gateway | All | All | standard | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CTX114028 - Hotfix AG2000_v455 Rev B - Access Gateway Standard Edition 4.5 - Citrix Knowledge Center | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Patch |
| Citrix EPA ActiveX Control Design Flaw | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Citrix EPA ActiveX Control Design Flaw - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CTX113815 - Vulnerabilities in Access Gateway Standard and Advanced Editions clients could result in arbitrary code execution - Citrix Knowledge Center | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| symantec.com has moved to broadcom.com | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | |
| osvdb.org/37845 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| www.securityfocus.com/bid/24975 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.