Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Positive Technologies maxpatrol8
|
|
| CPEs | cpe:2.3:a:positive_technologies:maxpatrol8:*:*:*:*:*:*:*:* cpe:2.3:a:positive_technologies:xspider:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Positive Technologies maxpatrol8
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Positive Technologies
Positive Technologies maxpatrol 8 Positive Technologies xspider |
|
| Vendors & Products |
Positive Technologies
Positive Technologies maxpatrol 8 Positive Technologies xspider |
Fri, 14 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption. | |
| Title | Positive Technologies MaxPatrol 8 & XSpider Remote DoS | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-14T22:51:47.690Z
Updated: 2025-11-18T16:33:01.126Z
Reserved: 2025-11-14T20:03:38.732Z
Link: CVE-2021-4467
Updated: 2025-11-18T16:32:30.167Z
Status : Awaiting Analysis
Published: 2025-11-14T23:15:42.557
Modified: 2025-11-18T17:15:57.190
Link: CVE-2021-4467
No data.