VULNERABILITY INTELLIGENCE

CVE-2011-2883

CVSS score9.3 HIGH
EPSS probability1.53%
CISA KEVNot currently listed
Published2011-07-21
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:C/I:C/A:C

Description

The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code via HTTP header data referencing a DLL that was signed with a crafted certificate.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references