Positive Technologies MaxPatrol 8 & XSpider Remote DoS
CVE-2021-4467
Key Information:
- Vendor
Positive Technologies
- Vendor
- CVE Published:
- 14 November 2025
Badges
What is CVE-2021-4467?
Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.
Affected Version(s)
MaxPatrol 8 (Server) 0 <= 09.2020
XSpider (Server) 0 <= 09.2020
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
