CVE-2020-8195
Description
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Summary dbcve.org
Improper input validation in Citrix ADC and Citrix Gateway and SDWAN WAN-OP allows authenticated low-privileged users to access limited information they should not be able to view. This is an access control bypass via crafted input rather than a direct injection flaw.
Mitigation
Upgrade Citrix ADC/Gateway to versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18 or later; upgrade SDWAN WAN-OP to 11.1.1a, 11.0.3d, 10.2.7 or later. Alternatively, restrict low-privilege user access until patches can be applied.