CVE-2010-4566
Summary
| CVE | CVE-2010-4566 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-14 23:00:47 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field. |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Access Gateway | .8.0 | m50.3 | enterprise | All |
| Application | Citrix | Access Gateway | 4.5 | All | advanced | All |
| Application | Citrix | Access Gateway | 4.5 | All | standard | All |
| Application | Citrix | Access Gateway | 4.5 | hf1 | All | All |
| Application | Citrix | Access Gateway | 4.5 | hf1 | advanced | All |
| Application | Citrix | Access Gateway | 4.5.5 | All | standard | All |
| Application | Citrix | Access Gateway | 4.5.6 | All | standard | All |
| Application | Citrix | Access Gateway | 4.5.7 | All | standard | All |
| Application | Citrix | Access Gateway | 4.6.1 | All | standard | All |
| Application | Citrix | Access Gateway | 4.6.2 | All | standard | All |
| Application | Citrix | Access Gateway | 4.6.3 | All | standard | All |
| Application | Citrix | Access Gateway | 8.0 | m48.7 | enterprise | All |
| Application | Citrix | Access Gateway | 8.0 | m49.2 | enterprise | All |
| Application | Citrix | Access Gateway | 8.0 | m59.1 | enterprise | All |
| Application | Citrix | Access Gateway | 8.1-69.4 | All | enterprise | All |
| Application | Citrix | Access Gateway | 9.0.71.3 | All | enterprise | All |
| Application | Citrix | Access Gateway | 9.1-104.5 | All | enterprise | All |
| Application | Citrix | Access Gateway | All | All | enterprise | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VSR Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.vsecurity.com | |
| Citrix Access Gateway Command Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Vulnerability in Citrix Access Gateway legacy authentication support could result in command injection | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Vendor Advisory |
| www.osvdb.org/70099 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityTracker: Citrix Access Gateway Flaw in Legacy NT Authentication Component Lets Remote Users Inject Commands | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Citrix Access Gateway Command Execution - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.