CVE-2006-6572
Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access…
Does this matter?
Lower severity and a low EPSS score (1.48%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than CVE-2006-4846. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.48% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- citrix/access gateway
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22909
- http://securitytracker.com/id?1017227Patch, Vendor Advisory
- http://support.citrix.com/article/CTX111614Patch, Vendor Advisory
- http://support.citrix.com/article/CTX111615
- http://www.securityfocus.com/bid/21080
- http://www.vupen.com/english/advisories/2006/4525
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30302
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30303
- http://secunia.com/advisories/22909
- http://securitytracker.com/id?1017227Patch, Vendor Advisory
- http://support.citrix.com/article/CTX111614Patch, Vendor Advisory
- http://support.citrix.com/article/CTX111615
- http://www.securityfocus.com/bid/21080
- http://www.vupen.com/english/advisories/2006/4525
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30302
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30303
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.