ZeroHour

CVE-2020-8193

KEV PoC mass

Unauthenticated Authorization Bypass in Citrix ADC, Gateway, and SD-WAN WANOP

CISA: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

CVSS 3.1
6.5 medium
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2020-8193 is an improper access control flaw (CWE-284/CWE-287) in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP appliances that lets an unauthenticated remote attacker reach certain URL endpoints that should require authentication. An attacker triggers it simply by sending crafted HTTP requests over the network, with no credentials or user interaction required. The direct impact is limited (CVSS 3.1 rates it 6.5 with low confidentiality and integrity impact), but access to protected endpoints can expose sensitive information and is commonly chained with other Citrix flaws; a public proof of concept for local file inclusion against Citrix ADC/NetScaler exists. Anyone running Citrix ADC or Gateway builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, or SD-WAN WAN-OP builds before 11.1.1a, 11.0.3d, or 10.2.7 is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog in November 2021 and was named in the NSA's list of the top 25 flaws actively exploited by Chinese state-sponsored hackers, with an EPSS probability of exploitation of 88.4%.

What to do: Upgrade Citrix ADC and Citrix Gateway to at least 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, and SD-WAN WAN-OP to at least 11.1.1a, 11.0.3d, or 10.2.7, per Citrix's instructions. Prioritize internet-facing ADC/Gateway appliances (VPN gateways and load balancers), since the flaw is reachable without credentials, and review appliance logs for unauthenticated access to protected endpoints. This CVE is on the CISA KEV list, so federal and KEV-committed defenders are required to apply the vendor updates.

Affected
Citrix ADC (NetScaler ADC) firmwareAll builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18
Citrix Gateway / NetScaler Gateway firmwareAll builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18
Citrix SD-WAN WAN-OP (WANOP appliance) firmwareAll builds before 11.1.1a, 11.0.3d, and 10.2.7
Estimated exposure
mass≈100,000+ internet-exposed Citrix ADC/Gateway appliances per public internet scans, with a substantially larger total installed base including internal… — Public internet-wide scans (e.g., Shodan-type scans) have repeatedly counted on the order of one hundred thousand Citrix ADC/NetScaler Gateway devices exposed to the internet, and these appliances are widely deployed at enterprises for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

CISA Known Exploited Vulnerability
Affected
Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
application delivery controller firmware, netscaler gateway firmware, gateway firmware, sd-wan wanop
Weakness
CWE-284, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news