CVE-2020-10111: High severity citrix gateway firmware vulnerability
Published Mar 6, 2020
·Updated
DISPUTED Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization.
Affected Software
3 affected components
Citrix Gateway Firmware=11.1
Citrix Gateway Firmware=12.0
Citrix Gateway Firmware=12.1
Event History
Mar 6, 2020
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Disputed
09:15 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Citrix Gateway issue?
The vulnerability ID for this Citrix Gateway issue is CVE-2020-10111.
2
What is the severity of CVE-2020-10111?
The severity of CVE-2020-10111 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2020-10111?
The Citrix Gateway firmware versions 11.1, 12.0, and 12.1 are affected by CVE-2020-10111.
4
What is the reported behavior of CVE-2020-10111?
The reported behavior of CVE-2020-10111 is an inconsistent interpretation of HTTP requests.
5
Is there a fix available for CVE-2020-10111?
Citrix disputes the reported behavior as not a security issue, so there may not be a patch specifically for CVE-2020-10111.