Lucene search

K
cveFlexeraCVE-2011-2592
HistoryJun 18, 2014 - 2:55 p.m.

CVE-2011-2592

2014-06-1814:55:11
CWE-119
flexera
web.nvd.nist.gov
110
cve
buffer overflow
nsepa.exe
citrix access gateway
activex control
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

High

EPSS

0.344

Percentile

97.1%

Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header.

Affected configurations

Nvd
Node
citrixaccess_gateway_plug-inMatch9.0enterprisewindows
OR
citrixaccess_gateway_plug-inMatch9.1enterprisewindows
OR
citrixaccess_gateway_plug-inMatch9.2enterprisewindows
OR
citrixaccess_gateway_plug-inMatch9.3enterprisewindows
OR
citrixaccess_gateway_plug-inMatch10.0enterprisewindows
VendorProductVersionCPE
citrixaccess_gateway_plug-in9.0cpe:2.3:a:citrix:access_gateway_plug-in:9.0:*:*:*:enterprise:windows:*:*
citrixaccess_gateway_plug-in9.1cpe:2.3:a:citrix:access_gateway_plug-in:9.1:*:*:*:enterprise:windows:*:*
citrixaccess_gateway_plug-in9.2cpe:2.3:a:citrix:access_gateway_plug-in:9.2:*:*:*:enterprise:windows:*:*
citrixaccess_gateway_plug-in9.3cpe:2.3:a:citrix:access_gateway_plug-in:9.3:*:*:*:enterprise:windows:*:*
citrixaccess_gateway_plug-in10.0cpe:2.3:a:citrix:access_gateway_plug-in:10.0:*:*:*:enterprise:windows:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

High

EPSS

0.344

Percentile

97.1%