CVE-2021-4467 Details
Description
Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.
A remote denial-of-service vulnerability has been identified in Positive Technologies MaxPatrol 8 and XSpider, both versions through September 2020. The issue resides in the client communication service on TCP port 2002, where the service generates a new session identifier for each incoming connection without properly limiting concurrent requests. This flaw allows an unauthenticated remote attacker to repeatedly send HTTPS requests to the service, leading to excessive session identifier allocation. Under heavy load, collisions may occur, causing active client sessions to disconnect and disrupting the service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 14, 2025CISA-ADP
Assessed Nov 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cxsecurity.com/issue/WLB-2021090114 | CISA-ADP | ExploitIssue TrackingTechnical Description |
| https://vulners.com/zdt/1337DAY-ID-36775 | CISA-ADP | Content WallExploit |
| https://cxsecurity.com/issue/WLB-2021090114 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vulners.com/zdt/1337DAY-ID-36775 | [email protected] | Content WallExploit |
| https://www.ptsecurity.com/ | [email protected] | |
| https://www.vulncheck.com/advisories/positive-technologies-maxpatrol-8-and-xspider-remote-dos | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Positive Technologies MaxPatrol 8 | <= 09.2020 |
CPE
Remediation
| |
| Positive Technologies XSpider | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | CVE Modified | CISA-ADP |
| Nov 14, 2025 | New CVE Received | [email protected] |
Volerion