PT-2025-47018 · Positive Technologies · Maxpatrol 8+1

Ascii

·

Published

2025-11-14

·

Updated

2025-11-15

·

CVE-2021-4467

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Positive Technologies MaxPatrol 8 (affected versions not specified) Positive Technologies XSpider (affected versions not specified)
Description The client communication service, listening on TCP port 2002, is susceptible to a remote denial-of-service condition. The service creates a new session identifier for each incoming connection but does not limit concurrent requests. An unauthenticated remote attacker can send repeated HTTPS requests to the service, leading to excessive session identifier allocation. This can cause session identifier collisions under load, resulting in the disconnection of active client sessions and service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-4467

Affected Products

Maxpatrol 8
Xspider