Input Validation Flaw in Citrix ADC and Gateway Products
CVE-2020-8245
Summary
An improper input validation vulnerability exists in Citrix ADC and Citrix Gateway products, specifically leading to potential HTML Injection attacks on the SSL VPN web portal. This flaw affects various versions of Citrix ADC and NetScaler Gateway, as well as Citrix SD-WAN WANOP products. Exploiting this vulnerability could allow an attacker to manipulate the web portal's behavior, leading to unauthorized actions and potentially compromising user data.
Affected Version(s)
Citrix ADC, Citrix Gateway Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved