CVE-2020-8300 is an improper access control vulnerability affecting Citrix ADC and Citrix/NetScaler Gateway versions prior to 13.0-82.41, 12.1-62.23, 11.1-65.20, and Citrix ADC 12.1-FIPS before 12.1-55.238. This medium-severity vulnerability (CVSS 6.5) allows for SAML authentication hijack through a phishing attack, enabling an attacker to steal a valid user session, provided the Citrix device is configured as a SAML Service Provider or Identity Provider. The attack requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to high integrity impact (I:H). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1, < 12.1-62.23CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.0-82.41CPE matchmatch criteria | cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1-65.20CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1-65.20CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 12.1, < 12.1-62.23CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.