PT-2001-2062 · Citrix · Citrix Metaframe

Published

2001-11-21

·

Updated

2017-12-19

·

CVE-2001-0908

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CITRIX Metaframe version 1.8
Description The issue allows clients to spoof their public IP address by logging the Client Address provided by the client instead of obtaining it from packet headers. This can be exploited through Network Address Translation (NAT).
Recommendations For CITRIX Metaframe version 1.8, consider implementing a mechanism to obtain the client's IP address from packet headers instead of relying on the client-provided address to prevent IP spoofing.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0908

Affected Products

Citrix Metaframe