← לוח פגיעויות

CVE-2020-8193

בינונית 6.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS — סבירות ניצול
88% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-284, CWE-287

מוצרים מושפעים

citrix: application delivery controller firmware; citrix: netscaler gateway firmware; citrix: gateway firmware; citrix: sd-wan wanop; citrix: 4000-wo; citrix: 4100-wo; citrix: 5000-wo; citrix: 5100-wo

קישורים