← לוח פגיעויות

CVE-2020-8195

בינונית 6.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
33% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-20, CWE-22

מוצרים מושפעים

citrix: application delivery controller firmware; citrix: netscaler gateway firmware; citrix: gateway firmware; citrix: sd-wan wanop; citrix: 4000-wo; citrix: 4100-wo; citrix: 5000-wo; citrix: 5100-wo; citrix: gateway plug-in for linux

קישורים