CVE Feed

    Dashboard / CVE / CVE-2021-4467

    CVE-2021-4467

    Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.

    Published:Nov 14, 2025
    Last Modified:Apr 15, 2026
    EPS:Nov 14, 2025
    EPSS Score:0.00115
    CVSS Score:8.7

    Affected Products

    Vendor
    Positive Technologies
    Product
    Maxpatrol8
    Vendor
    Positive Technologies
    Product
    Maxpatrol 8
    Vendor
    Positive Technologies
    Product
    Xspider

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High