CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
AV:N/AC:L/Au:N/C:P/I:P/A:P
This vulnerability has a 1.41% probability of being exploited in the next 30 days, ranking higher than 72% of all scored CVEs.