MEDIUM

CVE-2020-8195

Citrix Application Delivery Controller Firmware 2020-07-10 CVSS v3.1
CVSS
6.5
KEV

Description

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

Summary dbcve.org

Improper input validation in Citrix ADC and Citrix Gateway and SDWAN WAN-OP allows authenticated low-privileged users to access limited information they should not be able to view. This is an access control bypass via crafted input rather than a direct injection flaw.

Mitigation

Upgrade Citrix ADC/Gateway to versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18 or later; upgrade SDWAN WAN-OP to 11.1.1a, 11.0.3d, 10.2.7 or later. Alternatively, restrict low-privilege user access until patches can be applied.

Proof of Concept

Weakness (CWE)

CWE-20 Improper Input Validation
CWE-22 Path Traversal

EPSS Score

33.03%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE