Lucene search

K
cve[email protected]CVE-2007-2850
HistoryMay 24, 2007 - 6:30 p.m.

CVE-2007-2850

2007-05-2418:30:00
web.nvd.nist.gov
25
citrix
metaframe presentation server
session reliability service
network security
tcp ports
cve-2007-2850

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.063 Low

EPSS

Percentile

93.6%

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string.

Affected configurations

NVD
Node
citrixaccess_essentialsMatch1.0
OR
citrixaccess_essentialsMatch1.5
OR
citrixmetaframeMatch3.0microsoft_windows_2000
OR
citrixmetaframeMatch3.0microsoft_windows_2003
OR
citrixmetaframeMatch3.0x64_edition
OR
citrixmetaframeMatch4.0microsoft_windows_2000
OR
citrixmetaframeMatch4.0microsoft_windows_2003
OR
citrixmetaframeMatch4.0x64_edition

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.063 Low

EPSS

Percentile

93.6%

Related for CVE-2007-2850