Citrix Access Gateway Standard and Advanced Edition Unspecified Authentication Bypass Vulnerability
BID:29174
Info
Citrix Access Gateway Standard and Advanced Edition Unspecified Authentication Bypass Vulnerability
| Bugtraq ID: | 29174 |
| Class: | Unknown |
| CVE: |
CVE-2008-2528 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Citrix |
| Vulnerable: |
Citrix Access Gateway Standard Edition 4.5.7 Citrix Access Gateway Standard Edition 4.5.6 Citrix Access Gateway Standard Edition 4.5.5 Citrix Access Gateway Standard Edition 4.5 Citrix Access Gateway Advanced Edition 4.5 HF2 |
| Not Vulnerable: |
Citrix Access Gateway Standard Edition 4.5.7 Rev A |
Discussion
Citrix Access Gateway Standard and Advanced Edition Unspecified Authentication Bypass Vulnerability
Citrix Access Gateway Standard and Advanced Edition are prone to an unspecified authentication-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain unauthenticated access to network resources.
This issue affects Access Gateway Standard Edition 4.5.7 (and prior versions) and Advanced Edition 4.5 HF2 (and prior versions).
Citrix Access Gateway Standard and Advanced Edition are prone to an unspecified authentication-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain unauthenticated access to network resources.
This issue affects Access Gateway Standard Edition 4.5.7 (and prior versions) and Advanced Edition 4.5 HF2 (and prior versions).
Exploit / POC
Citrix Access Gateway Standard and Advanced Edition Unspecified Authentication Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Citrix Access Gateway Standard and Advanced Edition Unspecified Authentication Bypass Vulnerability
Solution:
The vendor has released firmware updates to address this issue. Please see the references for more information.
Citrix Access Gateway Standard Edition 4.5
Citrix Access Gateway Standard Edition 4.5.5
Citrix Access Gateway Standard Edition 4.5.6
Citrix Access Gateway Standard Edition 4.5.7
Solution:
The vendor has released firmware updates to address this issue. Please see the references for more information.
Citrix Access Gateway Standard Edition 4.5
-
Citrix Hotfix AG2000_V45_25418 - Access Gateway Standard Edition 4.5
https://www.citrix.com/English/myCitrix/loginNewUser.asp -
Citrix Hotfix AG2000_v457 Rev A - Access Gateway Standard Edition 4.5.7
http://support.citrix.com/article/CTX116762
Citrix Access Gateway Standard Edition 4.5.5
-
Citrix Hotfix AG2000_V45_25418 - Access Gateway Standard Edition 4.5
https://www.citrix.com/English/myCitrix/loginNewUser.asp -
Citrix Hotfix AG2000_v457 Rev A - Access Gateway Standard Edition 4.5.7
http://support.citrix.com/article/CTX116762
Citrix Access Gateway Standard Edition 4.5.6
-
Citrix Hotfix AG2000_V45_25418 - Access Gateway Standard Edition 4.5
https://www.citrix.com/English/myCitrix/loginNewUser.asp -
Citrix Hotfix AG2000_v457 Rev A - Access Gateway Standard Edition 4.5.7
http://support.citrix.com/article/CTX116762
Citrix Access Gateway Standard Edition 4.5.7
-
Citrix Hotfix AG2000_V45_25418 - Access Gateway Standard Edition 4.5
https://www.citrix.com/English/myCitrix/loginNewUser.asp -
Citrix Hotfix AG2000_v457 Rev A - Access Gateway Standard Edition 4.5.7
http://support.citrix.com/article/CTX116762
References
Citrix Access Gateway Standard and Advanced Edition Unspecified Authentication Bypass Vulnerability
References:
References: