CVE-2020-8275
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
Citrix Secure Mail para Android versiones anteriores a 20.11.0, sufre de un control de acceso inapropiado permitiendo el acceso no autenticado para leer datos limitados relacionados con el calendario almacenados dentro de Secure Mail. Tome en cuenta que una aplicación maliciosa necesitaría ser instalada en el dispositivo Android o un actor de amenazas necesitaría ejecutar código arbitrario en el dispositivo Android
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-28 CVE Reserved
- 2021-01-06 CVE Published
- 2023-12-13 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.citrix.com/article/CTX286763 | 2021-01-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Secure Mail Search vendor "Citrix" for product "Secure Mail" | < 20.11.0 Search vendor "Citrix" for product "Secure Mail" and version " < 20.11.0" | android |
Affected
|