MEDIUM

CVE-2020-8193

Citrix Application Delivery Controller Firmware 2020-07-10 CVSS v3.1
CVSS
6.5
KEV

Description

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

Summary dbcve.org

Improper access control in Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP allows unauthenticated attackers to access certain URL endpoints that should require authentication. This is an authentication bypass vulnerability affecting specific version ranges of all three products.

Mitigation

Upgrade Citrix ADC and Gateway to versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18 or later. Upgrade Citrix SDWAN WAN-OP to versions 11.1.1a, 11.0.3d, 10.2.7 or later.

Proof of Concept

Weakness (CWE)

CWE-284 Improper Access Control
CWE-287 Improper Authentication

EPSS Score

88.41%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE