First published: Fri Jul 10 2020(Updated: )
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Application Delivery Controller Firmware | >=10.5<10.5-70.18 | |
Citrix Application Delivery Controller Firmware | >=11.1<11.1-64.14 | |
Citrix Application Delivery Controller Firmware | >=12.0<12.0-63.21 | |
Citrix Application Delivery Controller Firmware | >=12.1<12.1-57.18 | |
Citrix Application Delivery Controller Firmware | >=13.0<13.0-58.30 | |
Citrix Application Delivery Controller | ||
Citrix Netscaler Gateway Firmware | >=10.5<10.5-70.18 | |
Citrix Netscaler Gateway Firmware | >=11.1<11.1-64.14 | |
Citrix Netscaler Gateway Firmware | >=12.0<12.0-63.21 | |
Citrix Netscaler Gateway Firmware | >=12.1<12.1-57.18 | |
Citrix NetScaler Gateway | ||
Citrix Gateway Firmware | >=13.0<13.0-58.30 | |
Citrix Gateway | ||
Citrix SD-WAN WANOP | >=10.2<10.2.7 | |
Citrix SD-WAN WANOP | >=11.0<11.0.3d | |
Citrix SD-WAN WANOP | >=11.1<11.1.1a | |
Citrix 4000-wo | ||
Citrix 4100-wo | ||
Citrix 5000-wo | ||
Citrix 5100-wo | ||
Citrix Gateway Plug-in For Linux | <1.0.0.137 | |
Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | ||
All of | ||
Any of | ||
Citrix Application Delivery Controller Firmware | >=10.5<10.5-70.18 | |
Citrix Application Delivery Controller Firmware | >=11.1<11.1-64.14 | |
Citrix Application Delivery Controller Firmware | >=12.0<12.0-63.21 | |
Citrix Application Delivery Controller Firmware | >=12.1<12.1-57.18 | |
Citrix Application Delivery Controller Firmware | >=13.0<13.0-58.30 | |
Citrix Application Delivery Controller | ||
All of | ||
Any of | ||
Citrix Netscaler Gateway Firmware | >=10.5<10.5-70.18 | |
Citrix Netscaler Gateway Firmware | >=11.1<11.1-64.14 | |
Citrix Netscaler Gateway Firmware | >=12.0<12.0-63.21 | |
Citrix Netscaler Gateway Firmware | >=12.1<12.1-57.18 | |
Citrix NetScaler Gateway | ||
All of | ||
Citrix Gateway Firmware | >=13.0<13.0-58.30 | |
Citrix Gateway | ||
All of | ||
Any of | ||
Citrix SD-WAN WANOP | >=10.2<10.2.7 | |
Citrix SD-WAN WANOP | >=11.0<11.0.3d | |
Citrix SD-WAN WANOP | >=11.1<11.1.1a | |
Any of | ||
Citrix 4000-wo | ||
Citrix 4100-wo | ||
Citrix 5000-wo | ||
Citrix 5100-wo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8195 is an information disclosure vulnerability in Citrix ADC Gateway and SD-WAN WANOP Appliance.
The severity of CVE-2020-8195 is medium with a CVSS score of 6.5.
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d, and 10.2.7 are affected.
The CWE of CVE-2020-8195 is CWE-20 (Improper Input Validation) and CWE-22 (Path Traversal).
To mitigate this vulnerability, it is recommended to update Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP Appliance to the fixed versions provided by Citrix.