PT-2001-2062 · Citrix · Citrix Metaframe
Published
2001-11-21
·
Updated
2017-12-19
·
CVE-2001-0908
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CITRIX Metaframe version 1.8
Description
The issue allows clients to spoof their public IP address by logging the Client Address provided by the client instead of obtaining it from packet headers. This can be exploited through Network Address Translation (NAT).
Recommendations
For CITRIX Metaframe version 1.8, consider implementing a mechanism to obtain the client's IP address from packet headers instead of relying on the client-provided address to prevent IP spoofing.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Citrix Metaframe