Citrix Access Gateway Standard and Advanced Edition Multiple Remote Vulnerabilities
BID:24975
Info
Citrix Access Gateway Standard and Advanced Edition Multiple Remote Vulnerabilities
| Bugtraq ID: | 24975 |
| Class: | Unknown |
| CVE: |
CVE-2007-0011 CVE-2007-4013 CVE-2007-4016 CVE-2007-4017 CVE-2007-4018 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Citrix credits Martin O�??Neal of Corsaire, Michael White of Symantec, and Paul Johnston for reporting the issues to them. |
| Vulnerable: |
Citrix Advanced Access Control 4.2 Citrix Advanced Access Control 4.0 Citrix Access Gateway Standard Edition 4.5 Citrix Access Gateway Advanced Edition 4.5 |
| Not Vulnerable: |
Citrix Advanced Access Control HF.1 Citrix Access Gateway Standard Edition 4.5.5 Citrix Access Gateway Advanced Edition 4.5.5 |
Discussion
Citrix Access Gateway Standard and Advanced Edition Multiple Remote Vulnerabilities
Citrix Access Gateway Standard and Advanced Edition are prone to multiple remote vulnerabilities. Exploiting these issues could allow an attacker to:
- Obtain sensitive information
- Execute code remotely
- Hijack sessions
- Redirect users to arbitrary sites
- Make unauthorized configuration changes
Citrix has released patches for these vulnerabilities.
Citrix Access Gateway Standard and Advanced Edition are prone to multiple remote vulnerabilities. Exploiting these issues could allow an attacker to:
- Obtain sensitive information
- Execute code remotely
- Hijack sessions
- Redirect users to arbitrary sites
- Make unauthorized configuration changes
Citrix has released patches for these vulnerabilities.
Exploit / POC
Citrix Access Gateway Standard and Advanced Edition Multiple Remote Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Citrix Access Gateway Standard and Advanced Edition Multiple Remote Vulnerabilities
Solution:
The vendor has released fixes to address these issues. Please the references for more information.
To mitigate the remote code-execution issues, follow the vendor's instructions.
Citrix Access Gateway Standard Edition 4.5
Citrix Access Gateway Advanced Edition 4.5
Solution:
The vendor has released fixes to address these issues. Please the references for more information.
To mitigate the remote code-execution issues, follow the vendor's instructions.
Citrix Access Gateway Standard Edition 4.5
-
Citrix Hotfix AG2000_v455 - Access Gateway Standard Edition 4.5
http://support.citrix.com/article/CTX114028
Citrix Access Gateway Advanced Edition 4.5
-
Citrix Hotfix AAC450W001 - For Access Gateway Advanced Edition 4.5
http://support.citrix.com/article/CTX112803
References
Citrix Access Gateway Standard and Advanced Edition Multiple Remote Vulnerabilities
References:
References:
- Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue ("advisories"
) - CTX113814: Vulnerabilities in Access Gateway Advanced Edition could result in in (Citrix )
- CTX113815: Vulnerabilities in Access Gateway Standard and Advanced Editions cli (Citrix )
- CTX113816: Vulnerabilities in Access Gateway Advanced Edition could allow redir (Citrix )
- CTX113817: Vulnerabilities in Access Gateway Standard and Advanced Edition coul (Citrix )