CVE-2007-3679
The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and…
Does this matter?
Lower severity and a low EPSS score (1.68%). Track it; it rarely justifies an emergency change on its own.
Description
The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.68% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- citrix/access gateway
- Source
- cve@mitre.org
References
- http://osvdb.org/37845
- http://secunia.com/advisories/26143Patch, Vendor Advisory
- http://securityreason.com/securityalert/2916
- http://support.citrix.com/article/CTX113815Patch
- http://support.citrix.com/article/CTX114028Patch
- http://www.securityfocus.com/archive/1/474204/100/0/threaded
- http://www.securityfocus.com/bid/24865
- http://www.securityfocus.com/bid/24975Patch
- http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-006.txt
- http://www.vupen.com/english/advisories/2007/2583
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35511
- http://osvdb.org/37845
- http://secunia.com/advisories/26143Patch, Vendor Advisory
- http://securityreason.com/securityalert/2916
- http://support.citrix.com/article/CTX113815Patch
- http://support.citrix.com/article/CTX114028Patch
- http://www.securityfocus.com/archive/1/474204/100/0/threaded
- http://www.securityfocus.com/bid/24865
- http://www.securityfocus.com/bid/24975Patch
- http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-006.txt
- http://www.vupen.com/english/advisories/2007/2583
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35511
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.