LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8196: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8196 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CVE-2020-8196 is an information disclosure vulnerability affecting Citrix Application Delivery Controller (ADC), Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models. It stems from improper access control (CWE-284), which can allow an attacker to obtain information that should not be exposed. For IT and security teams, this matters because these products often sit at the network edge, handling authentication, remote access, and application delivery—so leaked configuration or session-related data can aid further targeting.

Public detail on exact mechanics is limited; treat the vendor advisory as the authoritative source for affected builds, fixed releases, and any configuration caveats. CISA’s required action is to apply updates per vendor instructions. Ransomware use is not documented for this CVE.

How it works

The underlying weakness is CWE-284: improper access control. In products of this class, that typically means a resource, interface, or data path does not correctly enforce who is allowed to read certain information. An attacker who can reach the vulnerable surface may retrieve data the appliance should keep restricted—such as configuration details, status information, or other internal state—without proper authorization.

How that is abused in practice depends on the specific interface and authentication model of the appliance. Do not assume unauthenticated remote access, a particular HTTP endpoint, or a full compromise path unless the vendor advisory states it. Information disclosure alone does not equal remote code execution, but the data obtained can reduce the effort needed for follow-on attacks against the same devices or connected infrastructure. Confirm exploit preconditions, required privileges, and impact scope only against Citrix’s advisory for CVE-2020-8196.

Am I affected? How to find it in your systems

These components commonly run as network appliances or virtual appliances in DMZs, data centers, and remote-access architectures: load balancing and ADC front ends, SSL VPN / Gateway portals, and SD-WAN WANOP nodes. Inventory anything branded Citrix ADC (including legacy NetScaler naming in older deployments), Citrix Gateway, and Citrix SD-WAN WANOP.

If you cannot map a device to a clear build number, treat it as needing verification until confirmed patched or not affected.

How to remediate

Patch first. Apply the updates Citrix specifies for ADC, Gateway, and SD-WAN WANOP for CVE-2020-8196, following the vendor’s installation and reboot guidance. CISA directs organizations to apply updates per vendor instructions—schedule maintenance windows accordingly and verify the post-upgrade build string on every node, including HA pairs and DR copies.

If the advisory describes additional configuration changes beyond the software update, implement those as part of the same change.

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until the vendor update is installed.

Revisit the exception regularly; the durable fix remains the vendor-supplied update.

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to broader intrusion and data exposure even when the initial flaw is “only” information disclosure. If these appliances were unpatched and reachable while this issue was relevant, review access logs, assume sensitive configuration or session-related data may have been read, and follow your incident response process—credential rotation, session invalidation, and checks for follow-on activity on connected systems. Ransomware use is not documented for this CVE, but that does not rule out other misuse of disclosed information.

As a simple additional check for personal or work email addresses that may appear in third-party breach corpora, you can run a free exposure scan of your email to see whether those addresses appear in known breach data and then prioritize password changes and MFA accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
WeaknessCWE-284
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities