CVE-2020-8195 is an improper input validation vulnerability affecting multiple versions of Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP products. This flaw allows low-privileged users to achieve limited information disclosure. With a CVSS score of 6.5 (Medium), it has a network attack vector and low attack complexity, leading to high confidentiality impact without affecting integrity or availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in the CISA KEV catalog and mentions in NSA advisories regarding Chinese state-sponsored hacking. Despite no public Metasploit or ExploitDB modules, it garners significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.5, < 10.5-70.18CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1-64.14CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.0-63.21CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 12.1, < 12.1-57.18CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.0-58.30CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.