First published: Wed Jun 16 2021(Updated: )
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler Gateway | >=12.1<12.1-62.23 | |
Citrix NetScaler Gateway | >=13.0<13.0-82.41 | |
Citrix Netscaler Gateway Firmware | >=11.1<11.1-65.20 | |
Citrix Netscaler Application Delivery Controller Firmware | >=11.1<11.1-65.20 | |
Citrix Netscaler Application Delivery Controller Firmware | >=12.1<12.1-62.23 | |
Citrix Netscaler Application Delivery Controller Firmware | >=13.0<13.0-82.41 | |
Citrix Application Delivery Controller (ADC) and Gateway | ||
Citrix Netscaler Application Delivery Controller Firmware | >=12.1<12.1-55.238 | |
Citrix MPX/SDX 14030 FIPS | ||
Citrix MPX/SDX 14060 FIPS | ||
Citrix MPX/SDX 14080 FIPS | ||
Citrix MPX 15030-50G FIPS | ||
Citrix Mpx 15040-50g Fips | ||
Citrix MPX 15060-50G FIPS | ||
Citrix Mpx 15080-50g Fips | ||
Citrix Mpx 15100-50g Fips | ||
Citrix MPX | ||
Citrix Mpx 8905 Fips | ||
Citrix Mpx 8910 Fips | ||
Citrix MPX 8920 FIPS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-8300.
The severity level of CVE-2020-8300 is medium.
The affected software for CVE-2020-8300 includes Citrix ADC, Citrix/NetScaler Gateway, and Citrix Application Delivery Controller Firmware.
CVE-2020-8300 allows for improper access control, which can lead to SAML authentication hijack through a phishing attack and the ability to steal a valid user session.
You can find more information about CVE-2020-8300 at the following reference: [Citrix Support](https://support.citrix.com/article/CTX297155)