Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors.
Conclusion & alert: CVE-2006-4846 is rated Moderate Risk (49/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.80%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-02 | 5.97% | 3.80% | -2.17% |
| 2 | 2026-01-02 | 3.80% | 5.97% | +2.17% |
| 3 | 2025-10-13 | — | 3.80% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.1 | 2.0 | MEDIUM |
|
4.9 | 6.4 | [email protected] |
: Successful exploitation requires that the Advanced Access Control option is set to use LDAP authentication. This vulnerability is addressed by hotfix AAC420W004.
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| citrix | access_gateway | 4.2 | cpe:2.3:a:citrix:access_gateway:4.2:*:*:*:*:*:*:* |