|
Citrix contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when when a client makes a request on port 1604/udp to the Citrix server. This causes the server to disclose a list of Published Applications (PA) on the Citrix server. The PA enumeration could help an attacker to further attack the server using vulnerabilities in how Citrix handles .ICA files.
|