CVE-2020-8195: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Other sources
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Citrix ADCto a version that resolves this vulnerability.Fixed in 13.0-58.30 - Upgrade
Upgrade
Citrix ADCto a version that resolves this vulnerability.Fixed in 12.1-57.18 - Upgrade
Upgrade
Citrix ADCto a version that resolves this vulnerability.Fixed in 12.0-63.21 - Upgrade
Upgrade
Citrix ADCto a version that resolves this vulnerability.Fixed in 11.1-64.14 - Upgrade
Upgrade
Citrix ADCto a version that resolves this vulnerability.Fixed in 10.5-70.18 - Upgrade
Upgrade
Citrix Gatewayto a version that resolves this vulnerability.Fixed in 13.0-58.30 - Upgrade
Upgrade
Citrix Gatewayto a version that resolves this vulnerability.Fixed in 12.1-57.18 - Upgrade
Upgrade
Citrix Gatewayto a version that resolves this vulnerability.Fixed in 12.0-63.21 - Upgrade
Upgrade
Citrix Gatewayto a version that resolves this vulnerability.Fixed in 11.1-64.14 - Upgrade
Upgrade
Citrix Gatewayto a version that resolves this vulnerability.Fixed in 10.5-70.18 - Upgrade
Upgrade
Citrix SDWAN WAN-OPto a version that resolves this vulnerability.Fixed in 11.1.1a - Upgrade
Upgrade
Citrix SDWAN WAN-OPto a version that resolves this vulnerability.Fixed in 11.0.3d - Upgrade
Upgrade
Citrix SDWAN WAN-OPto a version that resolves this vulnerability.Fixed in 10.2.7
Event History
Frequently Asked Questions
What is CVE-2020-8195?
CVE-2020-8195 is an information disclosure vulnerability in Citrix ADC Gateway and SD-WAN WANOP Appliance.
What is the severity of CVE-2020-8195?
The severity of CVE-2020-8195 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2020-8195?
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d, and 10.2.7 are affected.
What is the CWE of CVE-2020-8195?
The CWE of CVE-2020-8195 is CWE-20 (Improper Input Validation) and CWE-22 (Path Traversal).
How can I fix CVE-2020-8195?
To mitigate this vulnerability, it is recommended to update Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP Appliance to the fixed versions provided by Citrix.