4.3
CVSSv2

CVE-2020-8245

Published: 18/09/2020 Updated: 07/10/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 prior to 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 prior to 12.1-58.15, Citrix ADC 12.1-FIPS prior to 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 prior to 11.1-65.12, Citrix SD-WAN WANOP 11.2 prior to 11.2.1a, Citrix SD-WAN WANOP 11.1 prior to 11.1.2a, Citrix SD-WAN WANOP 11.0 prior to 11.0.3f, Citrix SD-WAN WANOP 10.2 prior to 10.2.7b leads to an HTML Injection attack against the SSL VPN web portal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citrix application_delivery_controller_firmware

citrix gateway

citrix netscaler gateway

Vendor Advisories

Description of Problem Multiple vulnerabilities have been discovered in Citrix ADC (formerly known as NetScaler ADC), Citrix Gateway (formerly known as NetScaler Gateway) and Citrix SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO, and 5100-WO These vulnerabilities, if exploited, could result in the following securi ...