CVE-2002-0502

Citrix NFuse 1.6 - Unauthenticated Application Listing via applist.asp

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0502. PoCs published by Ian Vitek.

AI-analyzed exploit summary The code is a scanner for enumerating Citrix published applications via UDP port 1604, leveraging an information disclosure vulnerability in Citrix Nfuse. It includes tools for scanning, proxying, and connecting to published applications.

Description

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

Exploits (1)

exploitdb SCANNER VERIFIED
by Ian Vitek · perlremotewindows
https://www.exploit-db.com/exploits/21235

The code is a scanner for enumerating Citrix published applications via UDP port 1604, leveraging an information disclosure vulnerability in Citrix Nfuse. It includes tools for scanning, proxying, and connecting to published applications.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix Nfuse (version not specified)
No auth needed
Prerequisites: Network access to UDP port 1604 on the target · Citrix Nfuse server with published applications
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7984
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/251737
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/251923
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3926

Scores

EPSS 0.0359
EPSS Percentile 87.9%

Details

Status published
Products (1)
citrix/nfuse 1.6
Published Aug 12, 2002
Tracked Since Feb 18, 2026