Skip to content
COOEY

EXPOSURES › CVE-2020-8193

CVE-2020-8193

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8193 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Citrix ADC/Gateway/SD-WAN appliances suffer an authorization bypass allowing unauthenticated access to specific URL endpoints if the attacker has the NetScaler IP.

An authorization bypass vulnerability in Citrix ADC, Gateway, and SD-WAN WANOP appliances allows unauthenticated access to certain URL endpoints, provided the attacker has access to the NetScaler IP. This exposes sensitive data and enables further attacks, impacting DIB compliance by violating access control requirements. Organizations must patch these appliances immediately and restrict network access to the NetScaler IP.

Shame score — The vulnerability allows unauthenticated access to endpoints, which is a significant security flaw that could lead to data exposure and further exploitation, especially given Citrix's history of critical vulnerabilities.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.70
cooey ↗ negative -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized