CVE-2020-8209 is an improper access control vulnerability in multiple versions of Citrix XenMobile Server that allows an unauthenticated attacker to read arbitrary files on the server. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low attack complexity, and high impact on confidentiality. While not currently in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 99/100 indicate a significant likelihood of exploitation. Publicly available Nuclei templates exist for detecting this flaw, and it has garnered considerable community discussion and media coverage, including warnings from Citrix about potential exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.8.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:*:*:*:*:*:*:*:* | ||
10.9.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.9.0:-:*:*:*:*:*:* | ||
10.9.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch1:*:*:*:*:*:* | ||
10.9.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch2:*:*:*:*:*:* | ||
10.9.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.