CVE-2020-8199Improper Privilege Management in Citrix Gateway Plug-in FOR Linux

Severity
7.8HIGHNVD
EPSS
0.1%
top 67.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 24

Description

Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages9 packages

🔴Vulnerability Details

1
GHSA
GHSA-2v37-mp24-r94r: Improper access control in Citrix ADC Gateway Linux client versions before 12022-05-24

📋Vendor Advisories

2
Citrix
Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP appliance Security Update2020-08-17
Citrix
CVE-2020-8199: Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.2020-07-10

🕵️Threat Intelligence

1
Tenable
CVE-2020-8193, CVE-2020-8195, and CVE-2020-8196: Active Exploitation of Citrix Vulnerabilities2020-07-15