CVE-2010-4566
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/01/2011
Last modified:
11/04/2025
Description
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:citrix:access_gateway:*:*:enterprise:*:*:*:*:* | 9.2-49.8 (including) | |
| cpe:2.3:a:citrix:access_gateway:.8.0:m50.3:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:8.0:m48.7:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:8.0:m49.2:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:8.0:m59.1:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:8.1-69.4:*:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:9.0.71.3:*:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:9.1-104.5:*:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5:*:advanced:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5:*:standard:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5:hf1:*:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5:hf1:advanced:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5.5:*:standard:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5.6:*:standard:*:*:*:*:* | ||
| cpe:2.3:a:citrix:access_gateway:4.5.7:*:standard:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://securityreason.com/securityalert/8119
- http://support.citrix.com/article/CTX127613
- http://www.exploit-db.com/exploits/16916
- http://www.osvdb.org/70099
- http://www.securitytracker.com/id?1024893=
- http://www.vsecurity.com/resources/advisory/20101221-1
- http://securityreason.com/securityalert/8119
- http://support.citrix.com/article/CTX127613
- http://www.exploit-db.com/exploits/16916
- http://www.osvdb.org/70099
- http://www.securitytracker.com/id?1024893=
- http://www.vsecurity.com/resources/advisory/20101221-1



