← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-8300

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
EPSS Probability:3.01%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-284 ↗Improper Access Control - Generic (CWE-284)

Affected Products & Versions

Vendor Product Affected Versions
citrix gateway all
citrix netscaler_gateway all
citrix application_delivery_controller_firmware all
citrix application_delivery_controller all
citrix mpx\/sdx_14030_fips all
citrix mpx\/sdx_14060_fips all
citrix mpx\/sdx_14080_fips all
citrix mpx_15030-50g_fips all
citrix mpx_15040-50g_fips all
citrix mpx_15060-50g_fips all
citrix mpx_15080-50g_fips all
citrix mpx_15100-50g_fips all
citrix mpx_15120-50g_fips all
citrix mpx_8905_fips all
citrix mpx_8910_fips all
citrix mpx_8920_fips all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.010%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2020-01-28T00:00:00
Published2021-06-16T13:08:16
Last Updated2024-08-04T09:56:28

LINK COPIED TO CLIPBOARD