Vulnerability record · CVE-2020-8209 · published 17 August 2020
CVE-2020-8209: Citrix XenMobile Server improper access control allows arbitrary file read
Citrix · Xenmobile Server
Citrix XenMobile Server contains an improper access control flaw, classified as path traversal (CWE-22), that lets an attacker read arbitrary files. It affects multiple 10.x release trains before their respective rollup patches. Because the exposed data is read from the server itself, it can leak configuration and credential material used by the mobile device management platform.
Description
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file read with a CVSS of 7.5 and very high EPSS, though no confirmed exploitation or KEV listing.
What it is
Citrix XenMobile Server contains an improper access control flaw, classified as path traversal (CWE-22), that lets an attacker read arbitrary files. It affects multiple 10.x release trains before their respective rollup patches. Because the exposed data is read from the server itself, it can leak configuration and credential material used by the mobile device management platform.
Impact
An unauthenticated attacker can read arbitrary files on the XenMobile Server, exposing configuration, secrets or other sensitive data stored on the host. This is a confidentiality-only impact; there is no evidence in the record of code execution or data modification.
Attack surface
The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the XenMobile Server interface can attempt it. No authentication is required per the CVSS vector.
Exploitation
The record shows no CISA KEV listing and no exploit-tagged references; only vendor advisories are cited. EPSS is high at roughly 0.49 probability over 30 days (98.8th percentile), indicating elevated likelihood of attempted exploitation despite the absence of confirmed in-the-wild use.
What to do
- Apply the Citrix rollup patches: 10.12 RP2, 10.11 RP4, 10.10 RP6, or 10.9 RP5, per vendor advisory CTX277457.
- If patching cannot be done immediately, restrict network access to the XenMobile Server management interface to trusted hosts only.
- Rotate any credentials, tokens or certificates that may have been stored in files readable on the server.
- Monitor Citrix advisory CTX277457 for updated guidance and confirm the deployed build against the fixed rollup levels.
Detection
- Review web server and application logs for path traversal patterns (../, encoded variants) against XenMobile endpoints.
- Alert on unexpected outbound or internal requests to file-serving paths from unauthenticated clients.
- Baseline and monitor file access on the XenMobile host for reads of configuration or credential files by the web service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.citrix.com/article/CTX277457 | Vendor Advisory |
| https://support.citrix.com/article/CTX277457 | Vendor Advisory |
Track CVE-2020-8209 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8209), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.