PT-2011-4169 · Citrix · Citrix Access Gateway Enterprise Edition

Published

2011-07-21

·

Updated

2011-07-22

·

CVE-2011-2883

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Citrix Access Gateway Enterprise Edition versions 8.1 through 8.1-67.7 Citrix Access Gateway Enterprise Edition versions 9.0 through 9.0-70.5 Citrix Access Gateway Enterprise Edition versions 9.1 through 9.1-96.4
Description The issue allows man-in-the-middle attackers to execute arbitrary code via HTTP header data referencing a DLL that was signed with a crafted certificate. This is due to the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx attempting to validate signed DLLs by checking the certificate subject, not the signature.
Recommendations For Citrix Access Gateway Enterprise Edition versions 8.1 through 8.1-67.7, update to version 8.1-67.7 or later. For Citrix Access Gateway Enterprise Edition versions 9.0 through 9.0-70.5, update to version 9.0-70.5 or later. For Citrix Access Gateway Enterprise Edition versions 9.1 through 9.1-96.4, update to version 9.1-96.4 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2883

Affected Products

Citrix Access Gateway Enterprise Edition