PT-2020-20014 · Citrix · Citrix Gateway+1

Published

2020-07-10

·

Updated

2020-07-13

·

CVE-2020-8190

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix ADC and Citrix Gateway versions prior to 13.0-58.30 Citrix ADC and Citrix Gateway versions prior to 12.1-57.18 Citrix ADC and Citrix Gateway versions prior to 12.0-63.21 Citrix ADC and Citrix Gateway versions prior to 11.1-64.14 Citrix ADC and Citrix Gateway versions prior to 10.5-70.18
Description The issue is related to incorrect file permissions in Citrix ADC and Citrix Gateway, which allows privilege escalation.
Recommendations For versions prior to 13.0-58.30, update to version 13.0-58.30 or later. For versions prior to 12.1-57.18, update to version 12.1-57.18 or later. For versions prior to 12.0-63.21, update to version 12.0-63.21 or later. For versions prior to 11.1-64.14, update to version 11.1-64.14 or later. For versions prior to 10.5-70.18, update to version 10.5-70.18 or later.

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8190

Affected Products

Citrix Adc
Citrix Gateway