CVE-2020-8273: OS Command Injection
Published Nov 16, 2020
·Updated
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
Affected Software
3 affected components
Citrix SD-WAN>=10.2.0<10.2.8
Citrix SD-WAN>=11.1.0<11.1.2b
Citrix SD-WAN>=11.2.0<11.2.2
Event History
Nov 16, 2020
CVE Published
via MITRE·12:33 AM
Data Sourced
via MITRE·12:33 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8273?
CVE-2020-8273 has a high severity rating as it allows privilege escalation from authenticated users to root in affected Citrix SD-WAN versions.
2
How do I fix CVE-2020-8273?
To fix CVE-2020-8273, you should update Citrix SD-WAN to version 10.2.8 or later, 11.1.2b or later, or 11.2.2 or later.
3
What versions of Citrix SD-WAN are affected by CVE-2020-8273?
CVE-2020-8273 affects Citrix SD-WAN versions prior to 10.2.8, 11.1.2b, and 11.2.2.
4
Who can exploit CVE-2020-8273?
CVE-2020-8273 can be exploited by authenticated users with sufficient access to escalate their privileges to root.
5
Is there a workaround for CVE-2020-8273?
There is no documented workaround for CVE-2020-8273; upgrading to the fixed versions is recommended.