Vulnerability CVE-2009-2213


Published: 2009-06-25   Modified: 2012-02-13

Description:
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.

Type:

CWE-16

(Configuration)

Vendor: Citrix
Product: Netscaler access gateway firmware 
Version:
9.0
8.1
8.0
7.0
Product: Netscaler access gateway 

CVSS2 => (AV:N/AC:M/Au:S/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.3/10
6.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None

 References:
http://xforce.iss.net/xforce/xfdb/51274
http://www.vupen.com/english/advisories/2009/1641
http://www.securityfocus.com/bid/35422
http://support.citrix.com/article/CTX118770

Related CVE
CVE-2014-3798
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
CVE-2019-12292
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
CVE-2018-18571
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM...
CVE-2019-12044
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10...
CVE-2019-11634
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVE-2019-7218
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first au...
CVE-2019-7217
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
CVE-2019-6485
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 bef...

Copyright 2019, cxsecurity.com

 

Back to Top