CVE-2020-8194
Citrix application_delivery_controller_firmware Improper Control of Generation of Code ('Code Injection')
Record summary
CVE-2020-8194 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 31, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
application_delivery_controller_firmwareBrowse Citrix / application_delivery_controller_firmware | VulnCheck | Version data not supplied | |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | CVE List | Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMCitrix ADC and Citrix NetScaler Gateway - Remote Code InjectionCVSS 6.5
Citrix ADC and NetScaler Gateway are susceptible to remote code injection. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. Affected versions are before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18. Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allow modification of a file download.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Apply the necessary security patches or updates provided by Citrix to mitigate this vulnerability.
Source: ProjectDiscovery