CVE-2000-0244 describes a critical vulnerability in Citrix Metaframe and Winframe products, where the ICA protocol employs weak XOR encryption for user authentication. This flaw allows for unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 10.0. While there is no evidence of active exploitation in the wild or Metasploit modules, an exploit demonstrating weak encryption has been published on ExploitDB. Despite its age and high severity, there is no recorded community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8CPE matchmatch criteria | cpe:2.3:a:citrix:metaframe:*:*:windows_2000:*:*:*:*:* | ||
<= 1.8CPE matchmatch criteria | cpe:2.3:a:citrix:metaframe:*:*:windows_nt_4.0_tse:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:citrix:metaframe:1.0:*:unix:*:*:*:*:* | ||
3.5_1.8_for_windows_ntCPE matchmatch criteria | cpe:2.3:a:citrix:winframe:3.5_1.8_for_windows_nt:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.