« Volver al listado

CVE-2020-8200

Estado: ModificadaMedia (6.5)—

Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-8200",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Citrix StoreFront",
          "versions": [
            {
              "status": "affected",
              "version": "Citrix StoreFront 1912 CU1 (1912.0.1000), Citrix StoreFront 3.12 for 7.15 LTSR CU5 Hotfix (3.12.5001) and Citrix StoreFront 3.0 for 7.6 LTSR CU8 Hotfix (3.0.8001)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-18T21:15:12.827",
  "references": [
    {
      "url": "https://support.citrix.com/article/CTX277455",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://support.citrix.com/article/CTX277455",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server."
    },
    {
      "lang": "es",
      "value": "Una autenticación inapropiada en Citrix StoreFront Server versiones anteriores a 1912.0.1000, permite a un atacante que está autenticado en el mismo dominio del Microsoft Active Directory como un servidor Citrix StoreFront leer archivos arbitrarios de ese servidor"
    }
  ],
  "lastModified": "2026-06-17T03:26:02.577",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:citrix:storefront_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FA9A017-F874-442F-88EE-845BC261C984",
              "versionEndExcluding": "2006"
            },
            {
              "criteria": "cpe:2.3:a:citrix:storefront_server:*:*:*:*:ltsr:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "708F920E-7EC8-44A0-9722-41EE95F753C8",
              "versionEndExcluding": "3.0.8001",
              "versionStartIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:citrix:storefront_server:*:*:*:*:ltsr:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCFB4C56-A163-40E5-B705-560192D19290",
              "versionEndExcluding": "3.12.5001",
              "versionStartIncluding": "3.12"
            },
            {
              "criteria": "cpe:2.3:a:citrix:storefront_server:*:*:*:*:ltsr:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A1FABF8-B828-42BA-9534-443058E04DB6",
              "versionEndExcluding": "1912.0.1000",
              "versionStartIncluding": "1912"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}