CVE-2001-0908

CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).

Scoring

CVSS base score
0.03
EPSS probability
0.64%
Published
2002-02-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs