CVE-2020-8300: Medium severity citrix netscaler gateway vulnerability
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-8300.
What is the severity level of CVE-2020-8300?
The severity level of CVE-2020-8300 is medium.
What is the affected software for CVE-2020-8300?
The affected software for CVE-2020-8300 includes Citrix ADC, Citrix/NetScaler Gateway, and Citrix Application Delivery Controller Firmware.
What is the impact of CVE-2020-8300?
CVE-2020-8300 allows for improper access control, which can lead to SAML authentication hijack through a phishing attack and the ability to steal a valid user session.
Where can I find more information about CVE-2020-8300?
You can find more information about CVE-2020-8300 at the following reference: [Citrix Support](https://support.citrix.com/article/CTX297155)