CVE-2020-8194
medium · 6.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
6.5
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2020-07-10
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| citrix | application_delivery_controller_firmware | >= 10.5, < 10.5-70.18 |
| citrix | application_delivery_controller_firmware | >= 11.1, < 11.1-64.14 |
| citrix | application_delivery_controller_firmware | >= 12.0, < 12.0-63.21 |
| citrix | application_delivery_controller_firmware | >= 12.1, < 12.1-57.18 |
| citrix | application_delivery_controller_firmware | >= 13.0, < 13.0-58.30 |
| citrix | application_delivery_controller | all versions |
| citrix | netscaler_gateway_firmware | >= 10.5, < 10.5-70.18 |
| citrix | netscaler_gateway_firmware | >= 11.1, < 11.1-64.14 |
| citrix | netscaler_gateway_firmware | >= 12.0, < 12.0-63.21 |
| citrix | netscaler_gateway_firmware | >= 12.1, < 12.1-57.18 |
| citrix | netscaler_gateway | all versions |
| citrix | gateway_firmware | >= 13.0, < 13.0-58.30 |
| citrix | gateway | all versions |
| citrix | sd-wan_wanop | >= 10.2, < 10.2.7 |
| citrix | sd-wan_wanop | >= 11.0, < 11.0.3d |
| citrix | sd-wan_wanop | >= 11.1, < 11.1.1a |
| citrix | 4000-wo | all versions |
| citrix | 4100-wo | all versions |
| citrix | 5000-wo | all versions |
| citrix | 5100-wo | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-8194