Vulnerabilities > CVE-2020-13998 - Information Exposure Through Discrepancy vulnerability in Citrix Xenapp 6.5.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |