4.3
CVSSv3

CVE-2020-8196

Published: 10/07/2020 Updated: 20/09/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Improper access control in Citrix ADC and Citrix Gateway versions prior to 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions prior to 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citrix application_delivery_controller_firmware

citrix netscaler_gateway_firmware

citrix gateway_firmware

citrix sd-wan_wanop

Vendor Advisories

Description of Problem Multiple vulnerabilities have been discovered in Citrix ADC (formerly known as NetScaler ADC), Citrix Gateway (formerly known as NetScaler Gateway) and Citrix SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO, and 5100-WO These vulnerabilities, if exploited, could result in a number of security issues i ...
Description of Problem Multiple vulnerabilities have been discovered in Citrix ADC (formerly known as NetScaler ADC), Citrix Gateway (formerly known as NetScaler Gateway) and Citrix SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO, and 5100-WO These vulnerabilities, if exploited, could result in a number of security issues i ...

Exploits

This Metasploit module exploits a local file inclusion vulnerability in Citrix ADC Netscaler ...

Github Repositories

Scanning for CVE-2020-8193 - Auth Bypass check

CVE-2020-8193-Citrix-Scanner Scanning for CVE-2020-8193 - Auth Bypass check cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2020-8193 Supporting Documents: researchnccgroupcom/2020/07/10/rift-citrix-adc-vulnerabilities-cve-2020-8193-cve-2020-8195-and-cve-2020-8196-intelligence/ dmaaslandgithubio/posts/citrixhtml Disclaimer: I am not responsible for the u

This Metasploit-Framework module can be use to help companies to check the last Citrix vulnerability CVE-2020-8193, CVE-2020-8195 and CVE-2020-8196 (disclosed July 08, 2020).

citrix_adc_netscaler_lfi_scan This Metasploit-Framework module can be use to help companies to check the last Citrix vulnerabilites (disclosed July 08, 2020) CVE-2020-8193 CVE-2020-8195 CVE-2020-8196 Public reporting on July 8th, 2020 by Donny Maasland discussed how the vulnerability could be exploited As of July 10th, RIFT has confirmed that this vulnerability can be used

Recent Articles

FYI: Someone's scanning gateways, looking for those security holes Citrix told you not to worry too much about
The Register • Shaun Nichols in San Francisco • 09 Jul 2020

Hackers hit honeypots hours after CISO downplays risk, proof-of-concept exploit code emerges

VIdeo This week Citrix tried to reassure everyone the 11 security flaws it just patched in its network perimeter products weren't all that bad. Well, we hope they're right because someone's scanning the internet looking for vulnerable installations. The sweeps could be made by researchers documenting at-risk organizations, or could be miscreants looking for unpatched internet-facing gear to meddle with, or both. You probably don't want to find out the hard way, so apply fixes as soon as you can....

Citrix tells everyone not to worry too much about its latest security patches. NSA's former top hacker disagrees
The Register • Shaun Nichols in San Francisco • 08 Jul 2020

Eleven flaws cleaned up including one that may be exploited to sling malware downloads Australian PM says nation under serious state-run 'cyber attack' – Microsoft, Citrix, Telerik UI bugs 'exploited'

Citrix has issued patches for 11 CVE-listed security vulnerabilities in its various networking products. The bundle includes fixes for one code injection bug, three information disclosure flaws, three elevation of privilege bugs, two cross-site scripting vulnerabilities, one denial-of-service hole, and one authorization-bypass flaw. Affected gear includes the Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP. So far there have been no reports of any of the bug...