Vulnerability CVE-2007-3679


Published: 2007-07-25   Modified: 2012-02-12

Description:
The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system.

See advisories in our WLB2 database:
Topic
Author
Date
High
Citrix EPA ActiveX Control Design Flaw
Michael White
25.07.2007

Type:

CWE-Other

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Citrix -> Access gateway 

 References:
http://securityreason.com/securityalert/2916
http://support.citrix.com/article/CTX113815
http://support.citrix.com/article/CTX114028
http://www.securityfocus.com/archive/1/474204/100/0/threaded
http://www.securityfocus.com/bid/24865
http://www.securityfocus.com/bid/24975
http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-006.txt
http://www.vupen.com/english/advisories/2007/2583
https://exchange.xforce.ibmcloud.com/vulnerabilities/35511

Copyright 2022, cxsecurity.com

 

Back to Top