FAIL › dossier
Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
PRODUCT· dossier confidence 85%
This vendor's ADC/Gateway/SD-WAN appliances have a critical security track record, highlighted by a November 2021 cluster of vulnerabilities including an actively exploited RCE 0-day and multiple authorization bypasses.
PROFILE
CategoryNetwork Security ApplianceWhat they doApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance products.
SECURITY POSTURE
High-risk track record with multiple critical and high-severity vulnerabilities disclosed in November 2021, including an actively exploited RCE 0-day.
Notable failures
- CVE-2019-19781: Critical unauthenticated RCE 0-day actively exploited in the wild
- CVE-2020-8193: High-severity authorization bypass allowing unauthenticated access
- CVE-2020-8195: High-severity information disclosure vulnerability
- CVE-2020-8196: High-severity information disclosure vulnerability
Patterns: Multiple critical and high-severity vulnerabilities disclosed within a single month (Nov 2021); Unauthenticated remote code execution (RCE) vulnerabilities; Information disclosure vulnerabilities in ADC/Gateway appliances
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2019-19781 | critical | Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems. |
| 2021-11-03 | CVE-2020-8195 | high | Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days. |
| 2021-11-03 | CVE-2020-8196 | high | Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days. |
| 2021-11-03 | CVE-2020-8193 | high | Citrix ADC/Gateway/SD-WAN appliances suffer an authorization bypass allowing unauthenticated access to specific URL endpoints if the attacker has the NetScaler IP. |
DOSSIER SOURCES
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- Vulnerability Reports - Latest network security threats and zeroday ... · talosintelligence.com
Open questions: Current remediation status of CVE-2019-19781 and CVE-2020-8193/8195/8196 · Whether Citrix has implemented additional security controls to prevent similar vulnerabilities · Impact of these vulnerabilities on CMMC compliance for defense contractors using Citrix products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:56:01.291838+00:00