Junglewise Threat Intelligence

CVE-2020-8193: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

CVE-2020-8193 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2021-11-03

Technologies: Citrix Sd-Wan Wanop Appliance, Citrix Application Delivery Controller (ADC), Citrix Gateway. Vendors: Citrix.

Executive brief

Citrix ADC, Gateway, and SD-WAN WANOP appliances contain an authorization bypass vulnerability due to improper access control. An unauthenticated attacker with access to the NetScaler IP (NSIP) can gain unauthorized access to certain URL endpoints.

Affected products

  • Citrix ADC before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, 10.5-70.18
  • Citrix Gateway before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, 10.5-70.18
  • Citrix SD-WAN WANOP before 11.1.1a, 11.0.3d, 10.2.7

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats