CVE-2020-8253
Summary
| CVE | CVE-2020-8253 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-18 21:15:00 UTC |
| Updated | 2020-10-01 13:58:00 UTC |
| Description | Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Xenmobile Server | 10.10.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch5 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch5 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix Endpoint Management (CEM) Security Update | MISC | support.citrix.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.