CVE-2010-4566 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 27.8% (pctl 98)
Patch early
A public exploit exists.
Description
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 27.8% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-01-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| citrix | access gateway |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Citrix Access Gateway - Command Execution (Metasploit) | 2011-03-03 |
| exploit-db | Citrix Access Gateway - Command Injection | 2010-12-22 |
References
- http://securityreason.com/securityalert/8119
- http://support.citrix.com/article/CTX127613
- http://www.exploit-db.com/exploits/16916
- http://www.osvdb.org/70099
- http://www.securitytracker.com/id?1024893
- http://www.vsecurity.com/resources/advisory/20101221-1
- http://securityreason.com/securityalert/8119
- http://support.citrix.com/article/CTX127613
- http://www.exploit-db.com/exploits/16916
- http://www.osvdb.org/70099
- http://www.securitytracker.com/id?1024893
- http://www.vsecurity.com/resources/advisory/20101221-1
→ the Explorer · watch your stack · NVD