CVE-2020-8193
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
YesDecision
Descriptions
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
Un control de acceso inapropiado en Citrix ADC y Citrix Gateway versiones anteriores a 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 y 10.5-70.18 y Citrix SDWAN WAN-OP versiones anteriores a 11.1.1a, 11.0.3d y 10.2.7, permite un acceso no autenticado a determinados endpoints de URL
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-28 CVE Reserved
- 2020-07-10 CVE Published
- 2020-07-10 First Exploit
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2024-02-07 EPSS Updated
- 2024-08-04 CVE Updated
CWE
- CWE-284: Improper Access Control
- CWE-287: Improper Authentication
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/jas502n/CVE-2020-8193 | 2020-07-10 | |
https://github.com/Airboi/Citrix-ADC-RCE-CVE-2020-8193 | 2020-07-12 | |
https://github.com/PR3R00T/CVE-2020-8193-Citrix-Scanner | 2023-04-15 | |
https://github.com/ctlyz123/CVE-2020-8193 | 2020-07-15 | |
http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.citrix.com/article/CTX276688 | 2022-09-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | >= 10.5 < 10.5-70.18 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 10.5 < 10.5-70.18" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | >= 11.1 < 11.1-64.14 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 11.1 < 11.1-64.14" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | >= 12.0 < 12.0-63.21 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 12.0 < 12.0-63.21" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | >= 12.1 < 12.1-57.18 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 12.1 < 12.1-57.18" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | >= 13.0 < 13.0-58.30 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version " >= 13.0 < 13.0-58.30" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | >= 10.5 < 10.5-70.18 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version " >= 10.5 < 10.5-70.18" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | >= 11.1 < 11.1-64.14 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version " >= 11.1 < 11.1-64.14" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | >= 12.0 < 12.0-63.21 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version " >= 12.0 < 12.0-63.21" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | >= 12.1 < 12.1-57.18 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version " >= 12.1 < 12.1-57.18" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Gateway Firmware Search vendor "Citrix" for product "Gateway Firmware" | >= 13.0 < 13.0-58.30 Search vendor "Citrix" for product "Gateway Firmware" and version " >= 13.0 < 13.0-58.30" | - |
Affected
| in | Citrix Search vendor "Citrix" | Gateway Search vendor "Citrix" for product "Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 10.2 < 10.2.7 Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 10.2 < 10.2.7" | - |
Affected
| in | Citrix Search vendor "Citrix" | 4000-wo Search vendor "Citrix" for product "4000-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 10.2 < 10.2.7 Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 10.2 < 10.2.7" | - |
Affected
| in | Citrix Search vendor "Citrix" | 4100-wo Search vendor "Citrix" for product "4100-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 10.2 < 10.2.7 Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 10.2 < 10.2.7" | - |
Affected
| in | Citrix Search vendor "Citrix" | 5000-wo Search vendor "Citrix" for product "5000-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 10.2 < 10.2.7 Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 10.2 < 10.2.7" | - |
Affected
| in | Citrix Search vendor "Citrix" | 5100-wo Search vendor "Citrix" for product "5100-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.0 < 11.0.3d Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.0 < 11.0.3d" | - |
Affected
| in | Citrix Search vendor "Citrix" | 4000-wo Search vendor "Citrix" for product "4000-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.0 < 11.0.3d Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.0 < 11.0.3d" | - |
Affected
| in | Citrix Search vendor "Citrix" | 4100-wo Search vendor "Citrix" for product "4100-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.0 < 11.0.3d Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.0 < 11.0.3d" | - |
Affected
| in | Citrix Search vendor "Citrix" | 5000-wo Search vendor "Citrix" for product "5000-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.0 < 11.0.3d Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.0 < 11.0.3d" | - |
Affected
| in | Citrix Search vendor "Citrix" | 5100-wo Search vendor "Citrix" for product "5100-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.1 < 11.1.1a Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.1 < 11.1.1a" | - |
Affected
| in | Citrix Search vendor "Citrix" | 4000-wo Search vendor "Citrix" for product "4000-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.1 < 11.1.1a Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.1 < 11.1.1a" | - |
Affected
| in | Citrix Search vendor "Citrix" | 4100-wo Search vendor "Citrix" for product "4100-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.1 < 11.1.1a Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.1 < 11.1.1a" | - |
Affected
| in | Citrix Search vendor "Citrix" | 5000-wo Search vendor "Citrix" for product "5000-wo" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Sd-wan Wanop Search vendor "Citrix" for product "Sd-wan Wanop" | >= 11.1 < 11.1.1a Search vendor "Citrix" for product "Sd-wan Wanop" and version " >= 11.1 < 11.1.1a" | - |
Affected
| in | Citrix Search vendor "Citrix" | 5100-wo Search vendor "Citrix" for product "5100-wo" | - | - |
Safe
|