Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Positive Technologies
Positive Technologies maxpatrol 8 Positive Technologies xspider |
|
| Vendors & Products |
Positive Technologies
Positive Technologies maxpatrol 8 Positive Technologies xspider |
Fri, 14 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption. | |
| Title | Positive Technologies MaxPatrol 8 & XSpider Remote DoS | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-14T22:51:47.690Z
Updated: 2025-11-14T22:51:47.690Z
Reserved: 2025-11-14T20:03:38.732Z
Link: CVE-2021-4467
No data.
Status : Received
Published: 2025-11-14T23:15:42.557
Modified: 2025-11-14T23:15:42.557
Link: CVE-2021-4467
No data.
ReportizFlow