MEDIUM
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS)
Published Jul 10, 2020
6.1
MEDIUMCVSS 3.1
EPSS 26.14%
Description
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
Affected products
- Vendor n/a Product Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Defaultn/a
- Version Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | n/a |
|
Configuration 1
AND
OR
- ≥ 10.5 · < 10.5-70.18
- ≥ 11.1 · < 11.1-64.14
- ≥ 12.0 · < 12.0-63.21
- ≥ 12.1 · < 12.1-57.18
- ≥ 13.0 · < 13.0-58.30
Running on/with
- n/a
Configuration 2
AND
OR
- ≥ 10.5 · < 10.5-70.18
- ≥ 11.1 · < 11.1-64.14
- ≥ 12.0 · < 12.0-63.21
- ≥ 12.1 · < 12.1-57.18
Running on/with
- n/a
Configuration 3
AND
- ≥ 13.0 · < 13.0-58.30
Configuration 4
AND
OR
- ≥ 10.2 · < 10.2.7
- ≥ 11.0 · < 11.0.3d
- ≥ 11.1 · < 11.1.1a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://support.citrix.com/article/CTX276688 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.citrix.com/article/CTX276688 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jul 10, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
Link CVE-2020-8191
CISA Vulnrichment
Updated n/a