peter bassill · operator
$ cve CVE-2010-4566 JSON

CVE-2010-4566 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 27.8% (pctl 98)

Patch early

A public exploit exists.

Description

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS27.8% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2011-01-14
Last modified2026-06-16

Affected (1)

VendorProduct
citrixaccess gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD