CVE-2020-8196: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Other sources
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Citrix ADC / Citrix Gatewayto a version that resolves this vulnerability.Fixed in 13.0-58.30 - Upgrade
Upgrade
Citrix ADC / Citrix Gatewayto a version that resolves this vulnerability.Fixed in 12.1-57.18 - Upgrade
Upgrade
Citrix ADC / Citrix Gatewayto a version that resolves this vulnerability.Fixed in 12.0-63.21 - Upgrade
Upgrade
Citrix ADC / Citrix Gatewayto a version that resolves this vulnerability.Fixed in 11.1-64.14 - Upgrade
Upgrade
Citrix ADC / Citrix Gatewayto a version that resolves this vulnerability.Fixed in 10.5-70.18 - Upgrade
Upgrade
Citrix SD-WAN WAN-OPto a version that resolves this vulnerability.Fixed in 11.1.1a - Upgrade
Upgrade
Citrix SD-WAN WAN-OPto a version that resolves this vulnerability.Fixed in 11.0.3d - Upgrade
Upgrade
Citrix SD-WAN WAN-OPto a version that resolves this vulnerability.Fixed in 10.2.7
Event History
Frequently Asked Questions
What is CVE-2020-8196?
CVE-2020-8196 is an information disclosure vulnerability in Citrix ADC Gateway and SD-WAN WANOP Appliance.
What is the severity of CVE-2020-8196?
The severity of CVE-2020-8196 is medium with a CVSS score of 4.3.
What is affected by CVE-2020-8196?
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18, as well as Citrix SD-WAN WAN-OP versions before 11.1.1a, 11.0.3d, and 10.2.7 are affected by CVE-2020-8196.
How can I fix CVE-2020-8196?
Upgrade Citrix ADC and Citrix Gateway to versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, and upgrade Citrix SD-WAN WAN-OP to versions 11.1.1a, 11.0.3d, or 10.2.7 to fix CVE-2020-8196.
Where can I find more information about CVE-2020-8196?
You can find more information about CVE-2020-8196 on the following references: [Packet Storm Security](http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html) and [Citrix Support Article CTX276688](https://support.citrix.com/article/CTX276688).