MEDIUM KEV
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users
Published Jul 10, 2020 ·Due May 3, 2022
4.3
MEDIUMCVSS 3.1
EPSS 26.33%
Description
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Affected products
- Vendor n/a Product Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Defaultn/a
- Version Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | n/a |
|
Configuration 1
OR
- ≥ 10.5 · < 10.5-70.18
- ≥ 11.1 · < 11.1-64.14
- ≥ 12.0 · < 12.0-63.21
- ≥ 12.1 · < 12.1-57.18
- ≥ 13.0 · < 13.0-58.30
Configuration 2
OR
- ≥ 10.5 · < 10.5-70.18
- ≥ 11.1 · < 11.1-64.14
- ≥ 12.0 · < 12.0-63.21
- ≥ 12.1 · < 12.1-57.18
Configuration 3
- ≥ 13.0 · < 13.0-58.30
Configuration 4
AND
OR
- ≥ 10.2 · < 10.2.7
- ≥ 11.0 · < 11.0.3d
- ≥ 11.1 · < 11.1.1a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://support.citrix.com/article/CTX276688 x_refsource_MISCVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8196 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://support.citrix.com/article/CTX276688 | x_refsource_MISCVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8196 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jul 10, 2020
Updated Oct 21, 2025
Reserved Jan 28, 2020
Link CVE-2020-8196
CISA Vulnrichment
Updated Feb 7, 2025