Vulnerability Description
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Application Delivery Controller Firmware | >= 10.5, < 10.5-70.18 |
| Citrix | Application Delivery Controller | - |
| Citrix | Netscaler Gateway Firmware | >= 10.5, < 10.5-70.18 |
| Citrix | Netscaler Gateway | - |
| Citrix | Gateway Firmware | >= 13.0, < 13.0-58.30 |
| Citrix | Gateway | - |
References
- https://support.citrix.com/article/CTX276688Vendor Advisory
- https://support.citrix.com/article/CTX276688Vendor Advisory
FAQ
What is CVE-2020-8197?
CVE-2020-8197 is a vulnerability with a CVSS score of 8.8 (HIGH). Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to...
How severe is CVE-2020-8197?
CVE-2020-8197 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8197?
Check the references section above for vendor advisories and patch information. Affected products include: Citrix Application Delivery Controller Firmware, Citrix Application Delivery Controller, Citrix Netscaler Gateway Firmware, Citrix Netscaler Gateway, Citrix Gateway Firmware.