Medium severity5.4NVD Advisory· Published Mar 6, 2020· Updated Jun 17, 2026
CVE-2020-10112
CVE-2020-10112
Description
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:citrix:gateway_firmware:11.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:citrix:gateway_firmware:11.1:*:*:*:*:*:*:*
- cpe:2.3:o:citrix:gateway_firmware:12.0:*:*:*:*:*:*:*
- cpe:2.3:o:citrix:gateway_firmware:12.1:*:*:*:*:*:*:*
- Citrix/Citrix Gatewaydescription
- Range: 11.1, 12.0, and 12.1
Patches
Vulnerability mechanics
References
3- seclists.org/fulldisclosure/2020/Mar/8nvdExploitMailing ListThird Party Advisory
- support.citrix.com/searchnvdVendor Advisory
- packetstormsecurity.com/files/156660/Citrix-Gateway-11.1-12.0-12.1-Cache-Poisoning.htmlnvd
News mentions
0No linked articles in our index yet.