CVE-2011-2593 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix Access Gateway Plug-in
Severity
6.8MEDIUMNVD
EPSS
3.6%
top 12.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMay 17
Description
Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based buffer overflow.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages8 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-fxxh-pp9v-6qr6: Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa↗2022-05-17