Medium severity6.1NVD Advisory· Published Jul 10, 2020· Updated Jun 17, 2026
CVE-2020-8191
CVE-2020-8191
Description
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
Affected products
8- cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*Range: >=10.5,<10.5-70.18
- cpe:2.3:o:citrix:gateway_firmware:*:*:*:*:*:*:*:*Range: >=13.0,<13.0-58.30
- cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*Range: >=10.5,<10.5-70.18
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*range: >=10.2,<10.2.7
- (no CPE)range: <11.1.1a, 11.0.3d, 10.2.7
- Range: <13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, 10.5-70.18
- Range: <13.0-58.30
Patches
Vulnerability mechanics
References
1- support.citrix.com/article/CTX276688nvdVendor Advisory
News mentions
0No linked articles in our index yet.