CVE-2020-8299

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
hackeroneCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
citrixgateway
12.1 ≤
𝑥
< 12.1-61.18
citrixgateway
13.0 ≤
𝑥
< 13.0-76.29
citrixnetscaler_gateway
11.1 ≤
𝑥
< 11.1-65.20
citrixapplication_delivery_controller_firmware
11.1 ≤
𝑥
< 11.1-65.20
citrixapplication_delivery_controller_firmware
12.1 ≤
𝑥
< 12.1-61.18
citrixapplication_delivery_controller_firmware
13.0 ≤
𝑥
< 13.0-76.29
citrixapplication_delivery_controller_firmware
12.1 ≤
𝑥
< 12.1-55.238
citrixsd-wan_wanop
10.2 ≤
𝑥
< 10.2.9a
citrixsd-wan_wanop
11.1 ≤
𝑥
< 11.1.2c
citrixsd-wan_wanop
11.2 ≤
𝑥
< 11.2.3a
citrixsd-wan_wanop
11.3 ≤
𝑥
< 11.3.2
𝑥
= Vulnerable software versions