CVE-2020-8193
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP
Published 10 Jul 2020 · updated 17 Jun 2026 · Analyzed
6.5 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
References
- packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html · Exploit, Third Party Advisory, VDB Entry
- support.citrix.com/article/CTX276688 · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8193 · US Government Resource