>> Citrix Presentation Server Cryptographic Settings Bypass Issue
Title : Citrix Presentation Server Cryptographic Settings Bypass Issue VUPEN ID : VUPEN/ADV-2008-1531 CVE ID : CVE-2008-2299
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-14
Technical Description
A weakness has been identified in various Citrix products, which could result in cryptographic settings not being correctly enforced. This issue is caused due to the server allowing a client to establish a connection with encryption settings that are lower than the minimum configured by the administrator via the ICA protocol (SecureICA and ICA Basic encryption).