LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8195: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8195 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CVE-2020-8195 is an information disclosure vulnerability in Citrix Application Delivery Controller (ADC), Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models. It stems from improper input validation (CWE-20). For IT and security teams, this matters because these products often sit at the network edge and handle authentication, remote access, and application delivery; unintended disclosure of internal details can aid further attacks against the appliance or the environments behind it. Confirm exact scope and impact against the vendor advisory.

How it works

The underlying weakness is CWE-20, improper input validation. In products of this class, components that accept requests or configuration data may fail to adequately check or sanitize input before processing it. When that happens, an attacker who can reach the vulnerable interface may craft requests that cause the system to return information it should not expose—such as internal state, configuration fragments, or other data useful for reconnaissance.

Public detail on the precise request paths, parameters, or response contents for CVE-2020-8195 is limited in the material provided here. Do not assume unauthenticated remote exploitability, specific payloads, or particular data types without verifying against the Citrix advisory. Treat it as an information-disclosure issue that can lower the bar for follow-on activity if the appliance is reachable and unpatched. There is no documented association with ransomware use in the given facts.

Am I affected? How to find it in your systems

Citrix ADC and Gateway commonly appear as reverse proxies, load balancers, SSL VPN / remote-access gateways, and application delivery controllers. Citrix SD-WAN WANOP appliances are used in WAN optimization roles. Inventory any of these in DMZs, edge networks, data centers, and branch locations.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed builds or patches named in the Citrix advisory for CVE-2020-8195, schedule maintenance windows, and upgrade ADC, Gateway, and affected SD-WAN WANOP appliances according to Citrix’s documented procedures. Verify successful upgrade and that services return to expected operation.

After patching, harden for this weakness class:

If you can't patch immediately

Until you can apply the vendor update, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to broader compromise and data exposure even when the initial flaw is described as information disclosure. If these appliances were internet-facing and unpatched during the relevant period, investigate for unauthorized access, review related identity and application logs, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or identities have appeared in public breach sets, then prioritize password resets and MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities