← לוח פגיעויות

CVE-2020-8196

בינונית 4.3 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

מדדים

CVSS 3.1
4.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS — סבירות ניצול
26% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-284, CWE-287

מוצרים מושפעים

citrix: application delivery controller firmware; citrix: netscaler gateway firmware; citrix: gateway firmware; citrix: sd-wan wanop; citrix: 4000-wo; citrix: 4100-wo; citrix: 5000-wo; citrix: 5100-wo

קישורים