netVigilance Vulnerability intelligence since 2004
CVE-2020-8193 · netVigilance record NV21-0166

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass

past due

What to do

Apply updates per vendor instructions.

CISA deadline 2022-05-03 · passed 4 years 4 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA

What happened

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

Who is affected

Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.

Weakness class: CWE-284.

Timeline

  1. Added to CISA KEVExploitation in the wild confirmed by CISA
  2. CISA remediation deadlinepassed 4 years 4 months ago

Sources