Insufficient Secrets Protection in Citrix XenMobile Server by Citrix
CVE-2020-8210
7.5HIGH
Summary
This vulnerability relates to inadequate protection mechanisms in Citrix XenMobile Server that could result in the exposure of service account credentials. Specifically, certain versions of the server failed to securely manage sensitive information, allowing unauthorized parties to potentially access critical credentials, which could lead to further exploitation within the network.
Affected Version(s)
Citrix XenMobile Server Citrix XenMobile Server 10.12 RP3, Citrix XenMobile Server 10.11 RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved