Skip to content
COOEY

EXPOSURES › CVE-2020-8196

CVE-2020-8196

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8196 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatcheddata-breach

Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.

Citrix ADC, Gateway, and SD-WAN WANOP appliances contain an information disclosure vulnerability that allows attackers to extract sensitive data, a risk amplified by the vendor's November 2021 cluster of critical flaws including an actively exploited RCE 0-day. DIB organizations must urgently patch these systems to prevent data exfiltration and avoid reliance on a vendor with a demonstrably high-risk security track record.

Shame score — The flaw is actively exploited in the wild (KEV), involves a vendor with a recent history of critical RCE 0-days, and represents a severe breach of trust for a critical infrastructure component.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized