Skip to content
COOEY

EXPOSURES › CVE-2020-8195

CVE-2020-8195

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8195 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatcheddata-breach

Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.

Citrix ADC, Gateway, and SD-WAN WANOP appliances contain an information disclosure vulnerability that allows attackers to extract sensitive data, a risk amplified by the vendor's November 2021 cluster of critical flaws including an actively exploited RCE 0-day. DIB organizations must urgently patch these systems to prevent data exfiltration and avoid reliance on a vendor with a high-risk track record of critical and high-severity vulnerabilities.

Shame score — The flaw is actively exploited in the wild (KEV), involves information disclosure, and compounds a vendor with a recent history of critical RCE 0-days and authorization bypasses, indicating systemic negligence and a high-risk posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized