PT-2007-7142 · Citrix · Netscaler+2

Published

2007-12-07

·

Updated

2017-08-08

·

CVE-2007-6267

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Citrix EdgeSight versions 4.2 through 4.5 for Presentation Server Citrix EdgeSight versions 4.2 through 4.5 for Endpoints Citrix EdgeSight for NetScaler versions 1.0 through 1.1
Description The issue allows local users to obtain sensitive database credentials due to improper storage in configuration files.
Recommendations For Citrix EdgeSight versions 4.2 through 4.5 for Presentation Server, consider restricting access to configuration files until a proper fix is applied. For Citrix EdgeSight versions 4.2 through 4.5 for Endpoints, restrict access to configuration files to minimize the risk of exploitation. For Citrix EdgeSight for NetScaler versions 1.0 through 1.1, avoid using sensitive database credentials in configuration files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6267

Affected Products

Citrix Edgesight
Netscaler
Presentation Server