Vulnerability Description
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Gateway Firmware | 11.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156660/Citrix-Gateway-11.1-12.0-12.1-Cache-
- http://seclists.org/fulldisclosure/2020/Mar/8ExploitMailing ListThird Party Advisory
- https://support.citrix.com/searchVendor Advisory
- http://packetstormsecurity.com/files/156660/Citrix-Gateway-11.1-12.0-12.1-Cache-
- http://seclists.org/fulldisclosure/2020/Mar/8ExploitMailing ListThird Party Advisory
- https://support.citrix.com/searchVendor Advisory
FAQ
What is CVE-2020-10112?
CVE-2020-10112 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citr...
How severe is CVE-2020-10112?
CVE-2020-10112 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10112?
Check the references section above for vendor advisories and patch information. Affected products include: Citrix Gateway Firmware.