LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8193: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8193 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker…

CVE-2020-8193 is an authorization bypass vulnerability in Citrix Application Delivery Controller (ADC), Citrix Gateway, and certain Citrix SD-WAN WANOP appliances. It can allow an unauthenticated attacker who can reach the NetScaler IP (NSIP) to access certain URL endpoints that should require authorization. For organizations that expose management interfaces or place these devices in reachable network paths, the issue matters because it can open a path to unauthorized interaction with the appliance without valid credentials.

Public detail is limited to the authorization-bypass class and the NSIP access requirement; exact endpoint lists, version ranges, and exploitation mechanics must be confirmed against the vendor advisory.

How it works

The weakness is classified as CWE-284 (Improper Access Control). In products of this class, authorization checks that should gate sensitive management or configuration URLs can be incomplete or bypassable. An attacker who already has network reachability to the NetScaler IP (NSIP) may be able to invoke certain endpoints without authenticating, obtaining access that the device was intended to deny to unauthenticated parties.

No further exploit mechanics, payloads, or specific URL paths are provided in the available facts. Defenders should treat this as an unauthenticated authorization bypass conditioned on NSIP reachability and should rely on the vendor advisory for precise technical detail rather than assuming particular attack sequences.

Am I affected? How to find it in your systems

These products commonly sit at the edge or in DMZ/management segments as load balancers, SSL VPN/gateway appliances, or WAN optimization devices. Inventory any Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP appliances in your environment, including virtual and hardware form factors.

Telemetry signs of exploitation are not detailed in the public summary; treat anomalous unauthenticated access to restricted endpoints as suspicious and validate findings against vendor guidance.

How to remediate

Patch first. Apply the updates published by Citrix for ADC, Gateway, and SD-WAN WANOP exactly as described in the vendor advisory and per CISA’s direction to apply updates per vendor instructions. Confirm the specific builds that remediate CVE-2020-8193 on each appliance model you run.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

These steps lower risk but do not replace the vendor patch.

If your data may have been exposed

Actively exploited authorization-bypass issues on edge and management appliances can lead to further compromise or data exposure, though ransomware use is not documented for this CVE in the provided facts. If NSIP was reachable and you have indicators of unauthenticated access or unexplained configuration changes, follow your incident-response process: isolate affected devices where appropriate, preserve logs, rotate credentials and certificates that the appliance could have touched, and assess downstream systems that authenticate through or are load-balanced by the device. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
WeaknessCWE-284
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities