CVE-2021-4467
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-14

Last updated on: 2025-11-18

Assigner: VulnCheck

Description
Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-14
Last Modified
2025-11-18
Generated
2026-05-07
AI Q&A
2025-11-15
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
positive_technologies xspider 4.0
positive_technologies maxpatrol 4.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Positive Technologies MaxPatrol 8 and XSpider in the client communication service on TCP port 2002. The service creates a new session identifier for each incoming connection but does not properly limit the number of concurrent requests. An unauthenticated remote attacker can send repeated HTTPS requests to the service, causing excessive allocation of session identifiers. This can lead to session identifier collisions, which force active client sessions to disconnect and disrupt the service.


How can this vulnerability impact me? :

The vulnerability can cause a remote denial-of-service condition by forcing active client sessions to disconnect due to session identifier collisions. This results in service disruption, potentially making the affected service unavailable to legitimate users.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart