CVE-2020-8194: Code Injection
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8194?
CVE-2020-8194 is a vulnerability that allows the modification of a file download in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, as well as Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d, and 10.2.7.
What is the severity of CVE-2020-8194?
The severity of CVE-2020-8194 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2020-8194?
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, as well as Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d, and 10.2.7 are affected by CVE-2020-8194.
How does CVE-2020-8194 work?
CVE-2020-8194 allows an attacker to perform reflected code injection, which can be used to modify a file download.
Is there a fix for CVE-2020-8194?
Yes, Citrix has released patches to address the vulnerability. It is recommended to apply the latest updates to the affected software versions.