CVE-2001-0908
UnknownEPSS 1.41%
Last modified
CVE-2001-0908 is a vulnerability of currently unknown severity. CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Metaframe | 1.8 |
References
- http://www.securityfocus.com/bid/3566Vendor Advisory
- http://www.securityfocus.com/bid/3566Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0908?
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
How severe is CVE-2001-0908?
Severity scoring for CVE-2001-0908 is pending analysis. The EPSS model estimates a 1.41% probability of exploitation in the next 30 days.
How do I fix CVE-2001-0908?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0902Microsoft IIS 5.0 allows remote attackers to spoof web log e…
- CVE-2001-0903Linear key exchange process in High-bandwidth Digital Conten…
- CVE-2001-0904Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patc…
- CVE-2001-0905Race condition in signal handling of procmail 3.20 and earli…
- CVE-2001-0906teTeX filter before 1.0.7 allows local users to gain privile…
- CVE-2001-0907Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10,…
- CVE-2001-0909Buffer overflow in helpctr.exe program in Microsoft Help Cen…
- CVE-2001-0910Legato Networker before 6.1 allows remote attackers to bypas…
- CVE-2001-0911PHP-Nuke 5.1 stores user and administrator passwords in a ba…
- CVE-2001-0912Packaging error for expect 8.3.3 in Mandrake Linux 8.1 cause…
- CVE-2001-0913Format string vulnerability in Network Solutions Rwhoisd 1.5…
- CVE-2001-0914Linux kernel before 2.4.11pre3 in multiple Linux distributio…
Are you affected by CVE-2001-0908?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
