CVE-2020-8300

MEDIUM

Citrix ADC and Gateway < 13.0-82.41, 12.1-62.23, 11.1-65.20 - SAML Authentication Hijack via Session Theft

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-8300. PoCs published by stuartcarroll.

AI-analyzed exploit summary This PowerShell script detects Citrix ADC configurations vulnerable to CVE-2020-8300 by checking for SAML actions or SAML iDP profiles without relaystaterule or acsurlrule parameters. It uses the Citrix ADC NITRO API to authenticate and query configurations.

Description

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

Exploits (1)

nomisec SCANNER 1 stars
by stuartcarroll · poc
https://github.com/stuartcarroll/CitrixADC-CVE-2020-8300

This PowerShell script detects Citrix ADC configurations vulnerable to CVE-2020-8300 by checking for SAML actions or SAML iDP profiles without relaystaterule or acsurlrule parameters. It uses the Citrix ADC NITRO API to authenticate and query configurations.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix ADC
Auth required
Prerequisites: Valid Citrix ADC credentials · Network access to Citrix ADC management interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.citrix.com/article/CTX297155

Scores

CVSS v3 6.5
EPSS 0.1495
EPSS Percentile 94.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (3)
citrix/application_delivery_controller_firmware 11.1 - 11.1-65.20
citrix/gateway 12.1 - 12.1-62.23
citrix/netscaler_gateway 11.1 - 11.1-65.20
Published Jun 16, 2021
Tracked Since Feb 18, 2026