CVE-2020-8299: Medium severity citrix netscaler gateway vulnerability
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8299?
CVE-2020-8299 is a vulnerability in Citrix ADC and Citrix/NetScaler Gateway that allows for uncontrolled resource consumption by way of a network-based denial-of-service attack.
Which versions of Citrix ADC and Citrix/NetScaler Gateway are affected by CVE-2020-8299?
Citrix ADC and Citrix/NetScaler Gateway versions 13.0 before 13.0-76.29, 12.1 before 12.1-61.18, and 11.1 before 11.1-65.20 are affected by CVE-2020-8299.
How severe is CVE-2020-8299?
CVE-2020-8299 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2020-8299?
To fix CVE-2020-8299, update your Citrix ADC or Citrix/NetScaler Gateway software to versions 13.0-76.29, 12.1-61.18, or 11.1-65.20.
Where can I find more information about CVE-2020-8299?
You can find more information about CVE-2020-8299 in the Citrix support article: https://support.citrix.com/article/CTX297155