CVE-2020-8196
KEVlargeInformation disclosure flaw in Citrix ADC, Gateway, and SD-WAN WANOP appliances
CISA: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVE-2020-8196 is an improper access control (CWE-284) issue in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP appliances that results in information disclosure. An unauthenticated attacker who can reach the appliance's web interface can retrieve limited configuration details, including the password hash of the primary administrative account (nsroot), without logging in. That information can be used for follow-on actions such as offline password cracking and deeper compromise of the appliance. Organizations running affected builds of Citrix ADC, Citrix Gateway, or Citrix SD-WAN WANOP appliances are in scope. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation; no public proof-of-concept is cataloged and ransomware use is unconfirmed.
What to do: Apply the fixed builds Citrix supplies per vendor instructions (Citrix advisory CTX276688 lists affected and fixed ADC/Gateway builds; the SD-WAN WANOP advisory lists the applicable appliance builds). Prioritize internet-facing ADC/Gateway devices, restrict management-interface access to trusted networks, and rotate the primary/nsroot password on any appliance that may have been accessed since the flaw's disclosure.
| Citrix Application Delivery Controller (ADC) | — |
| Citrix Gateway | — |
| Citrix SD-WAN WANOP Appliance (multiple models) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
- Affected
- Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- application delivery controller firmware, netscaler gateway firmware, gateway firmware, sd-wan wanop
- Weakness
- CWE-284, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N