Citrix ADC and Citrix NetScaler Gateway Multiple Vulnerabilities (CTX276688)

high Nessus Plugin ID 138212

Synopsis

The remote device is affected by multiple vulnerabilities.

Description

The remote Citrix ADC or Citrix NetScaler Gateway device is version 10.5.x prior to 10.5-70.18, 11.1.x prior to 11.1-64.14, 12.0.x prior to 12.0-63.21, 12.1.x prior to 12.1-57.18, 12.1-FIPS prior to 12.1-55.179 or 13.0.x prior to 13.0-58.30.
It is, therefore, affected by multiple vulnerabilities:

- An authorization bypass vulnerability exists in Citrix ADC and NetScaler Gateway devices. An unauthenticated remote attacker with access to the NSIP/management interface can exploit this to bypass authorization. (CVE-2020-8193)

- A code injection vulnerability exists in Citrix ADC and NetScaler Gateway devices. An unauthenticated remote attacker with access to the NSIP/management interface can exploit this to create a malicious file which, if executed by a victim on the management network, could allow the attacker arbitrary code execution in the context of that user. (CVE-2020-8194)

- A cross-site scripting vulnerability exists in Citrix ADC and NetScaler Gateway devices. An unauthenticated remote attacker can exploit this convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session. (CVE-2020-8191, CVE-2020-8198)

In addition, Citrix ADC and Citrix NetScaler Gateway are also affected by several additional vulnerabilities including configuration-dependent privilege escalations, information disclosures, and a denial of service vulnerability.

Please refer to advisory CTX276688 for more information.

Solution

For versions 10.5.x, 11.1.x, 12.0.x, 12.1.x and 13.0.x, upgrade to 10.5.70.18, 11.1.64.14, 12.0.63.21, 12.1.57.18 and 13.0.58.30, or later, respectively.

See Also

https://support.citrix.com/article/CTX276688

Plugin Details

Severity: High

ID: 138212

File Name: citrix_netscaler_CTX276688.nasl

Version: 1.12

Type: combined

Family: CGI abuses

Published: 7/8/2020

Updated: 2/12/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2020-8197

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:citrix:netscaler_gateway, cpe:/h:citrix:netscaler_application_delivery_controller

Required KB Items: Host/NetScaler/Detected

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/7/2020

Vulnerability Publication Date: 7/7/2020

CISA Known Exploited Vulnerability Due Dates: 5/3/2022

Reference Information

CVE: CVE-2019-18177, CVE-2020-8187, CVE-2020-8190, CVE-2020-8191, CVE-2020-8193, CVE-2020-8194, CVE-2020-8195, CVE-2020-8196, CVE-2020-8197, CVE-2020-8198, CVE-2020-8199

IAVA: 2020-A-0286-S