Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 3, 2022

CVE-2020-8193

High
CVSS 6.5EPSS 94.3%CISA KEVPoC Available
Citrix/Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Description

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

CVSS Score

6.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS — Exploit Probability

94.3%

Higher than 99.9% of all CVEs

Weakness Classification (CWE)

CWE-284CWE-284MITRE

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2020-8193

Risk Assessment

CRITICAL
In CISA KEV
Known exploit
High EPSS

Details

Severity
High
CVSS
6.5
EPSS
94.3%
CWE
CWE-284
Exploit
POC
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

May 3, 2022

Affected Product

Citrix

Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

View all Citrix CVEs