← Back to browse · API

CVE-2020-8193

Severity
MEDIUM
CVSS
6.5
EPSS
0.88411
Risk score
81.94
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-29070, GHSA-WRXP-682M-VM9P
Products
Citrix:Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance, n/a:Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7
Sources
euvd EUVD-2020-29070
cisa.gov CVE-2020-8193

Description

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

References