Skip to content
COOEY

FAIL › dossier

Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

PRODUCT

· dossier confidence 85%

This vendor's ADC/Gateway/SD-WAN appliances have a critical security track record, highlighted by a November 2021 cluster of vulnerabilities including an actively exploited RCE 0-day and multiple authorization bypasses.

PROFILE
CategoryNetwork Security ApplianceWhat they doApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance products.
SECURITY POSTURE

High-risk track record with multiple critical and high-severity vulnerabilities disclosed in November 2021, including an actively exploited RCE 0-day.

Notable failures
  • CVE-2019-19781: Critical unauthenticated RCE 0-day actively exploited in the wild
  • CVE-2020-8193: High-severity authorization bypass allowing unauthenticated access
  • CVE-2020-8195: High-severity information disclosure vulnerability
  • CVE-2020-8196: High-severity information disclosure vulnerability
Patterns: Multiple critical and high-severity vulnerabilities disclosed within a single month (Nov 2021); Unauthenticated remote code execution (RCE) vulnerabilities; Information disclosure vulnerabilities in ADC/Gateway appliances
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2019-19781 critical Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems.
2021-11-03 CVE-2020-8195 high Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
2021-11-03 CVE-2020-8196 high Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
2021-11-03 CVE-2020-8193 high Citrix ADC/Gateway/SD-WAN appliances suffer an authorization bypass allowing unauthenticated access to specific URL endpoints if the attacker has the NetScaler IP.
Open questions: Current remediation status of CVE-2019-19781 and CVE-2020-8193/8195/8196 · Whether Citrix has implemented additional security controls to prevent similar vulnerabilities · Impact of these vulnerabilities on CMMC compliance for defense contractors using Citrix products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:56:01.291838+00:00