MEDIUM · 6.5

CVE-2020-8300

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack th...

Vulnerability Description

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CitrixGateway>= 12.1, < 12.1-62.23
CitrixNetscaler Gateway>= 11.1, < 11.1-65.20
CitrixApplication Delivery Controller Firmware>= 11.1, < 11.1-65.20
CitrixApplication Delivery Controller-
CitrixMpx\/Sdx 14030 Fips-
CitrixMpx\/Sdx 14060 Fips-
CitrixMpx\/Sdx 14080 Fips-
CitrixMpx 15030-50G Fips-
CitrixMpx 15040-50G Fips-
CitrixMpx 15060-50G Fips-
CitrixMpx 15080-50G Fips-
CitrixMpx 15100-50G Fips-
CitrixMpx 15120-50G Fips-
CitrixMpx 8905 Fips-
CitrixMpx 8910 Fips-
CitrixMpx 8920 Fips-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8300?

CVE-2020-8300 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack th...

How severe is CVE-2020-8300?

CVE-2020-8300 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8300?

Check the references section above for vendor advisories and patch information. Affected products include: Citrix Gateway, Citrix Netscaler Gateway, Citrix Application Delivery Controller Firmware, Citrix Application Delivery Controller, Citrix Mpx\/Sdx 14030 Fips.