MEDIUM
CVE-2020-8193
CVSS
6.5
KEV
Description
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
Summary dbcve.org
Improper access control in Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP allows unauthenticated attackers to access certain URL endpoints that should require authentication. This is an authentication bypass vulnerability affecting specific version ranges of all three products.
Mitigation
Upgrade Citrix ADC and Gateway to versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18 or later. Upgrade Citrix SDWAN WAN-OP to versions 11.1.1a, 11.0.3d, 10.2.7 or later.
Weakness (CWE)
CWE-284
Improper Access Control
CWE-287
Improper Authentication
EPSS Score
88.41%
Probability of exploitation in next 30 days
99.8th percentile
References
http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html
Exploit, Third Party Advisory, VDB Entry
https://support.citrix.com/article/CTX276688
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8193
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.