ZeroHour

CVE-2020-8196

KEVlarge

Information disclosure flaw in Citrix ADC, Gateway, and SD-WAN WANOP appliances

CISA: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

CVSS 3.1
4.3 medium
EPSS
26%p98
Published
()
KEV added
AI analysis

CVE-2020-8196 is an improper access control (CWE-284) issue in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP appliances that results in information disclosure. An unauthenticated attacker who can reach the appliance's web interface can retrieve limited configuration details, including the password hash of the primary administrative account (nsroot), without logging in. That information can be used for follow-on actions such as offline password cracking and deeper compromise of the appliance. Organizations running affected builds of Citrix ADC, Citrix Gateway, or Citrix SD-WAN WANOP appliances are in scope. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation; no public proof-of-concept is cataloged and ransomware use is unconfirmed.

What to do: Apply the fixed builds Citrix supplies per vendor instructions (Citrix advisory CTX276688 lists affected and fixed ADC/Gateway builds; the SD-WAN WANOP advisory lists the applicable appliance builds). Prioritize internet-facing ADC/Gateway devices, restrict management-interface access to trusted networks, and rotate the primary/nsroot password on any appliance that may have been accessed since the flaw's disclosure.

Affected
Citrix Application Delivery Controller (ADC)
Citrix Gateway
Citrix SD-WAN WANOP Appliance (multiple models)
Estimated exposure
largeon the order of tens of thousands of internet-exposed Citrix ADC/Gateway appliances, within an installed base in the hundreds of thousands — Citrix ADC/Gateway are widely deployed enterprise edge/gateway devices and public internet scans during 2020-2021 consistently showed tens of thousands of exposed instances, while WANOP branch-appliance deployments are a smaller subset.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

CISA Known Exploited Vulnerability
Affected
Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
application delivery controller firmware, netscaler gateway firmware, gateway firmware, sd-wan wanop
Weakness
CWE-284, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news