Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
This indicates an attack attempt to exploit a Authentication Bypass Vulnerability in Citrix ADC, Gateway, and SDWAN WAN-OP.This vulnerability is due to improper authentication on certain HTTP endpoints in the vulnerable application. Successful exploitation could lead to the elevation of privileges for unauthenticated users.
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18
Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7
Privilege Escalation: Remote attackers can leverage their privileges on vulnerable systems.
Apply the most recent upgrade or patch from the vendor.
https://support.citrix.com/article/CTX276688
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
MarcelBilal | https://github.com/ipcis/Citrix_ADC_Gateway_Check | Source MarcelBilal 1609225688229318661 | 2023/01/01 |
MarcelBilal | https://twitter.com/MarcelBilal/status/1609225688229318661/... | Source MarcelBilal 1609225688229318661 | 2023/01/01 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
lists.astaro.com | 16 |
canyoupwn.me | 6 |
github.com | 4 |
twitter.com | 4 |
tweetedtimes.com | 4 |
support.citrix.com | 4 |
dmaasland.github.io | 4 |
bit.ly | 3 |
www.tenable.com | 3 |
newsbythehour.org | 3 |
www.checkpoint.com | 3 |
www.proofpoint.com | 3 |
research.nccgroup.com | 3 |
ipssignatures.appspot.com | 3 |
User | URL | Info Source |
---|---|---|
MarcelBilal | github.com | Show Tweet |
MarcelBilal | twitter.com | Show Tweet |
Name | URL |
---|---|
jas502n/CVE-2020-8193 | https://github.com/jas502n/CVE-2020-8193 |
Airboi/Citrix-ADC-RCE-CVE-2020-8193 | https://github.com/Airboi/Citrix-ADC-RCE-CVE-2020-8193 |
PR3R00T/CVE-2020-8193-Citrix-Scanner | https://github.com/PR3R00T/CVE-2020-8193-Citrix-Scanner |
Zeop-CyberSec/citrix_adc_netscaler_lfi | https://github.com/Zeop-CyberSec/citrix_adc_netscaler_lfi |
ctlyz123/CVE-2020-8193 | https://github.com/ctlyz123/CVE-2020-8193 |
Name | URL |
---|---|
jas502n/CVE-2020-8193 | github.com |
Airboi/Citrix-ADC-RCE-CVE-2020-8193 | github.com |
PR3R00T/CVE-2020-8193-Citrix-Scanner | github.com |
Zeop-CyberSec/citrix_adc_netscaler_lfi | github.com |
ctlyz123/CVE-2020-8193 | github.com |