MEDIUM · 5.0

CVE-2008-2299

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker...

Vulnerability Description

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftWindows 2003 ServerAll versions
CitrixPresentation Server<= 4.5
CitrixAccess Essentials<= 2.0
CitrixDesktop Server1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2299?

CVE-2008-2299 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker...

How severe is CVE-2008-2299?

CVE-2008-2299 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2299?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2003 Server, Citrix Presentation Server, Citrix Access Essentials, Citrix Desktop Server.