CVE-2020-8193
KEV PoC massUnauthenticated Authorization Bypass in Citrix ADC, Gateway, and SD-WAN WANOP
CISA: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
CVE-2020-8193 is an improper access control flaw (CWE-284/CWE-287) in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP appliances that lets an unauthenticated remote attacker reach certain URL endpoints that should require authentication. An attacker triggers it simply by sending crafted HTTP requests over the network, with no credentials or user interaction required. The direct impact is limited (CVSS 3.1 rates it 6.5 with low confidentiality and integrity impact), but access to protected endpoints can expose sensitive information and is commonly chained with other Citrix flaws; a public proof of concept for local file inclusion against Citrix ADC/NetScaler exists. Anyone running Citrix ADC or Gateway builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, or SD-WAN WAN-OP builds before 11.1.1a, 11.0.3d, or 10.2.7 is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog in November 2021 and was named in the NSA's list of the top 25 flaws actively exploited by Chinese state-sponsored hackers, with an EPSS probability of exploitation of 88.4%.
What to do: Upgrade Citrix ADC and Citrix Gateway to at least 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, and SD-WAN WAN-OP to at least 11.1.1a, 11.0.3d, or 10.2.7, per Citrix's instructions. Prioritize internet-facing ADC/Gateway appliances (VPN gateways and load balancers), since the flaw is reachable without credentials, and review appliance logs for unauthenticated access to protected endpoints. This CVE is on the CISA KEV list, so federal and KEV-committed defenders are required to apply the vendor updates.
| Citrix ADC (NetScaler ADC) firmware | All builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18 |
| Citrix Gateway / NetScaler Gateway firmware | All builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18 |
| Citrix SD-WAN WAN-OP (WANOP appliance) firmware | All builds before 11.1.1a, 11.0.3d, and 10.2.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
- Affected
- Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- application delivery controller firmware, netscaler gateway firmware, gateway firmware, sd-wan wanop
- Weakness
- CWE-284, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N