CVE-2007-6267

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
07/12/2007
Last modified:
09/04/2025

Description

Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:citrix:edgesight_for_endpoints:4.2:*:*:*:*:*:*:*
cpe:2.3:a:citrix:edgesight_for_endpoints:4.5:*:*:*:*:*:*:*
cpe:2.3:a:citrix:edgesight_for_netscaler:1.0:*:*:*:*:*:*:*
cpe:2.3:a:citrix:edgesight_for_netscaler:1.1:*:*:*:*:*:*:*
cpe:2.3:a:citrix:edgesight_for_presentation_server:4.2:*:*:*:*:*:*:*
cpe:2.3:a:citrix:edgesight_for_presentation_server:4.5:*:*:*:*:*:*:*