Input Validation Flaw in Citrix ADC and Gateway Products
CVE-2020-8245

6.1MEDIUM

Key Information:

Vendor
Citrix
Vendor
CVE Published:
18 September 2020

Summary

An improper input validation vulnerability exists in Citrix ADC and Citrix Gateway products, specifically leading to potential HTML Injection attacks on the SSL VPN web portal. This flaw affects various versions of Citrix ADC and NetScaler Gateway, as well as Citrix SD-WAN WANOP products. Exploiting this vulnerability could allow an attacker to manipulate the web portal's behavior, leading to unauthorized actions and potentially compromising user data.

Affected Version(s)

Citrix ADC, Citrix Gateway Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.