PT-2020-13827 · Citrix · Citrix Xenapp

Jill Kamperides

+1

·

Published

2020-06-11

·

Updated

2024-08-04

·

CVE-2020-13998

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Citrix XenApp version 6.5
Description The issue allows a remote unauthenticated attacker to determine whether a user exists on the server when two-factor authentication (2FA) is enabled. This is because the 2FA error page is only displayed after a valid username is entered. The products affected by this issue are no longer supported by the maintainer.
Recommendations For Citrix XenApp version 6.5, as the product is no longer supported, there is no information about a newer version that contains a fix for this issue.

Fix

IDOR

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2020-13998

Affected Products

Citrix Xenapp