EXPOSURES › CVE-2020-8195
CVE-2020-8195
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
Citrix ADC, Gateway, and SD-WAN WANOP appliances contain an information disclosure vulnerability that allows attackers to extract sensitive data, a risk amplified by the vendor's November 2021 cluster of critical flaws including an actively exploited RCE 0-day. DIB organizations must urgently patch these systems to prevent data exfiltration and avoid reliance on a vendor with a high-risk track record of critical and high-severity vulnerabilities.
Shame score — The flaw is actively exploited in the wild (KEV), involves information disclosure, and compounds a vendor with a recent history of critical RCE 0-days and authorization bypasses, indicating systemic negligence and a high-risk posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |