CVE-2020-8193
KEVMEDIUM 6.5EPSS 88.4%
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 88.41% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03
- Nuclei
- medium
- Published
- 2020-07-10
- Updated
- 2025-10-21
Proof-of-concept exploits (4)
- http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html
- Airboi/Citrix-ADC-RCE-CVE-2020-819345★ · 2020-07-12
- ctlyz123/CVE-2020-81932★ · 2020-07-15
- jas502n/CVE-2020-819388★ · 2020-07-10
Nuclei templates (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/citrix-cve-2020-8193-unauthorized.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2020/CVE-2020-8193.yaml