Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
BID:20066
CVE-2006-4846 |Info
Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
| Bugtraq ID: | 20066 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2006 12:00AM |
| Updated: | Sep 18 2006 11:21PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Citrix Access Gateway AAC 4.2 |
| Not Vulnerable: | |
Discussion
Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
Citrix Access Gateway is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass LDAP authentication and gain unauthorized access to the application.
Citrix Access Gateway is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass LDAP authentication and gain unauthorized access to the application.
Exploit / POC
Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
An attacker can use standard network tools to exploit this issue.
An attacker can use standard network tools to exploit this issue.
Solution / Fix
Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
Solution:
The vendor has released updates to address this issue.
Please see the referenced advisories for more information.
Citrix Access Gateway AAC 4.2
Solution:
The vendor has released updates to address this issue.
Please see the referenced advisories for more information.
Citrix Access Gateway AAC 4.2
-
Citrix AAC420W004.zip
http://support.citrix.com/servlet/KbServlet/download/11002-102-15244/A AC420W004.zip
References
Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
References:
References: