CVE-2020-8195
KEV PoC largeInformation Disclosure (Improper Input Validation) in Citrix ADC, Gateway, SD-WAN WANOP
CISA: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVE-2020-8195 is an information disclosure vulnerability in Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models, rooted in improper input validation (CWE-20). An attacker can trigger the flaw by getting the affected appliance to process crafted or malformed input, causing it to disclose sensitive information that could support further attacks against the appliance or the environment behind it. Organizations running these Citrix edge appliances — particularly ADC/Gateway deployments handling application delivery and remote access, and enterprises using SD-WAN WANOP for WAN optimization — are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware association unknown), and EPSS assigns it a high 33.3% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CISA's required action is to apply updates per vendor instructions.
What to do: Apply the latest patched firmware to Citrix ADC, Gateway, and SD-WAN WANOP appliances per Citrix's security bulletin — the exact affected version ranges and fixed releases are in the vendor advisory — prioritizing internet-facing devices, as required by the CISA KEV listing. Because this is an information disclosure flaw, review appliance logs and consider rotating credentials, secrets, or configuration data that may have been exposed. Inventory all ADC/Gateway/SD-WAN WANOP deployments, including appliances reachable only internally, and confirm each is running a fixed build.
| Citrix Application Delivery Controller (ADC) | — |
| Citrix Gateway | — |
| Citrix SD-WAN WANOP Appliance (multiple models) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
- Affected
- Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- application delivery controller firmware, netscaler gateway firmware, gateway firmware, sd-wan wanop, gateway plug-in for linux
- Weakness
- CWE-20, CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N