PT-2016-7656 · Citrix · Citrix Receiver Desktop Lock
Rithwik Jayasimha
·
Publicado
2016-11-07
·
Atualizado
2017-09-06
·
CVE-2016-9111
CVSS v3.1
6.8
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Citrix Receiver Desktop Lock version 4.5
Description
The issue concerns incorrect access control mechanisms, potentially allowing an attacker to bypass authentication requirements. This could be achieved by leveraging physical access to a Virtual Desktop Infrastructure (VDI) and temporarily disconnecting a LAN cable. It's noted that the vendor was unable to reproduce the issue despite extensive investigation.
Recommendations
For Citrix Receiver Desktop Lock version 4.5, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Citrix Receiver Desktop Lock