CVE-2020-8195
medium · 6.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
6.5
CVSS
33.0%
EPSS (exploit prob.)
98th
EPSS percentile
2020-07-10
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-20CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| citrix | application_delivery_controller_firmware | >= 10.5, < 10.5-70.18 |
| citrix | application_delivery_controller_firmware | >= 11.1, < 11.1-64.14 |
| citrix | application_delivery_controller_firmware | >= 12.0, < 12.0-63.21 |
| citrix | application_delivery_controller_firmware | >= 12.1, < 12.1-57.18 |
| citrix | application_delivery_controller_firmware | >= 13.0, < 13.0-58.30 |
| citrix | netscaler_gateway_firmware | >= 10.5, < 10.5-70.18 |
| citrix | netscaler_gateway_firmware | >= 11.1, < 11.1-64.14 |
| citrix | netscaler_gateway_firmware | >= 12.0, < 12.0-63.21 |
| citrix | netscaler_gateway_firmware | >= 12.1, < 12.1-57.18 |
| citrix | gateway_firmware | >= 13.0, < 13.0-58.30 |
| citrix | sd-wan_wanop | >= 10.2, < 10.2.7 |
| citrix | sd-wan_wanop | >= 11.0, < 11.0.3d |
| citrix | sd-wan_wanop | >= 11.1, < 11.1.1a |
| citrix | 4000-wo | all versions |
| citrix | 4100-wo | all versions |
| citrix | 5000-wo | all versions |
| citrix | 5100-wo | all versions |
| citrix | gateway_plug-in_for_linux | < 1.0.0.137 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html
- https://support.citrix.com/article/CTX276688
- http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html
- https://support.citrix.com/article/CTX276688
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8195
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-8195