Evidence dossier

CVE-2020-8195

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before…

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 6.5. EPSS estimates 33.3% exploit likelihood as of Aug 27, 2026.

72.873.8Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

State
PUBLISHED
Published
Jul 10, 2020
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    hackerone

    Record text: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

    Inspect raw assertion
    Field
    container
    Value
    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 33.26% probability · 98.24th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.332630000000; percentile 0.982420000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood33.26%

FIRST EPSS · score date Aug 27, 2026 · 98.2th percentile · first observed Aug 27, 2026

SeverityCVSS 6.5

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
hackeroneOriginal assertion
Record text

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

Inspect raw assertion
Field
container
Value
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

33.26% probability · 98.24th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.332630000000; percentile 0.982420000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
18Underlying assertions
9Canonical products
14Target assertions
4Constraint assertions

Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

10 scope groups

hackerone · source assertedn/aCitrix ADC, Citrix Gateway, Citrix SDWAN WAN-OPDirect source scope
Affected: Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7"}]
NVD CPE · HARDWAREcitrix4000-woEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-98fcae2ae6d2752c623c0ed03c9699850ca4b63c15cb621a8ff54dc7089e1304Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:citrix:4000-wo:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    25c848bc-98f7-41d4-a262-8b7eb304f4c1
NVD CPE · HARDWAREcitrix4100-woEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-139ca63c52fa78ebb047d205cf9e057d89e047f2c8337431068aa66d7d5194ccLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:citrix:4100-wo:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f3979eff-ae6e-4274-97e2-58c7e01c920e
NVD CPE · HARDWAREcitrix5000-woEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-6de83eda976806c6ae4aec3b63e5410a577376818492b85638320ef5733f9314Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:citrix:5000-wo:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c87af39e-6bcf-4188-bab1-a5cbdebf662e
NVD CPE · HARDWAREcitrix5100-woEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-06e6bab86cb6a4d9dc75b1078ba73782f06d2e0405ef7b702e7c1a3309aaff48Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:citrix:5100-wo:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    38514675-1c15-460c-b34c-2633a8a36a78
NVD CPE · OPERATING SYSTEMcitrixapplication_delivery_controller_firmwareVulnerable target · 5 assertions
Any version (unconstrained) (>= 10.5, < 10.5-70.18); Any version (unconstrained) (>= 11.1, < 11.1-64.14); Any version (unconstrained) (>= 12.0, < 12.0-63.21); Any version (unconstrained) (>= 12.1, < 12.1-57.18); Any version (unconstrained) (>= 13.0, < 13.0-58.30)Canonical identity product-74f89a03a794cfd5616f30fe592f30eb465dda6c915da7e76ed8b8c72bac689bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 12.0; through excluding 12.0-63.21
    Match ID
    165076f2-014f-46f9-a1ab-2256d935a21b
  2. cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 12.1; through excluding 12.1-57.18
    Match ID
    d6ae49e6-a6b9-4e2b-9afb-7f1808d052f6
  3. cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.5; through excluding 10.5-70.18
    Match ID
    fc8327d0-8b64-44af-a230-aae32f3526cf
  4. cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 13.0; through excluding 13.0-58.30
    Match ID
    03868d24-b1c0-4245-ae28-0960cf2816c1
  5. cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 11.1; through excluding 11.1-64.14
    Match ID
    d4807513-1157-4ce3-8998-9c5eb9bbda3e
NVD CPE · OPERATING SYSTEMcitrixgateway_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (>= 13.0, < 13.0-58.30)Canonical identity product-829994e2b3ac7aea9e17116454437c3851ed8a99c09dcfe4202719f57a4c29a9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:citrix:gateway_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.0; through excluding 13.0-58.30
    Match ID
    e6d0cc10-fe91-40e4-bffd-11be41dd4269
NVD CPE · APPLICATIONcitrixgateway_plug-in_for_linuxVulnerable target · 1 assertions
Any version (unconstrained) (< 1.0.0.137)Canonical identity product-40ee6da5b05c5a3f0a90157ac9a9c9a5a2d2367af0cacd44f92e01a2369c1bd7Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:citrix:gateway_plug-in_for_linux:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 1.0.0.137
    Match ID
    25969217-eb50-466a-9f0f-5deb1805b27d
NVD CPE · OPERATING SYSTEMcitrixnetscaler_gateway_firmwareVulnerable target · 4 assertions
Any version (unconstrained) (>= 10.5, < 10.5-70.18); Any version (unconstrained) (>= 11.1, < 11.1-64.14); Any version (unconstrained) (>= 12.0, < 12.0-63.21); Any version (unconstrained) (>= 12.1, < 12.1-57.18)Canonical identity product-21abd5a5f37a71ec35390b4587ab5a2d4c6695610a7c8d41c95e2049552310f0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 12.1; through excluding 12.1-57.18
    Match ID
    6fa8946f-75c2-4515-9ebe-e1884b35ecf1
  2. cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 11.1; through excluding 11.1-64.14
    Match ID
    61c33096-91fd-4387-8b90-c8981db7f926
  3. cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.5; through excluding 10.5-70.18
    Match ID
    ba7aac01-a7cb-48f4-a25d-4a29479cd0da
  4. cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 12.0; through excluding 12.0-63.21
    Match ID
    7605821f-21b0-4f9d-aad1-f901ced00585
NVD CPE · OPERATING SYSTEMcitrixsd-wan_wanopVulnerable target · 3 assertions
Any version (unconstrained) (>= 10.2, < 10.2.7); Any version (unconstrained) (>= 11.0, < 11.0.3d); Any version (unconstrained) (>= 11.1, < 11.1.1a)Canonical identity product-5dde4c9cb73aecdcebabe94977fd047e4f6d666c43d098158c9e7086fbdcf9c3Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 11.0; through excluding 11.0.3d
    Match ID
    1d1a5e7d-c3a7-48b8-bd6d-5973f8361dec
  2. cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.2; through excluding 10.2.7
    Match ID
    b7df63bb-cce6-4405-8e6d-6df1bc975d3d
  3. cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 11.1; through excluding 11.1.1a
    Match ID
    0471f1f0-f804-47ba-98a1-7080e1c740e7

Affected-product evidence

Accepted scope and product mapping

5 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-613dd4bb79ad8759a10407fe624cb651bdb422f3f2780231736f064b614ee756 · product-21abd5a5f37a71ec35390b4587ab5a2d4c6695610a7c8d41c95e2049552310f0

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
370a5ecf-d807-4f8c-932f-0bb3e86a0b46465dbb38-cfde-4bb9-9e31-c13fb68d502e49bcc9e4-5378-4014-bc97-2f1a220eaebacc17fffe-5e0a-44fa-9fac-63c1d6327e81
Mapping establishedEvidence supported

vendor-613dd4bb79ad8759a10407fe624cb651bdb422f3f2780231736f064b614ee756 · product-40ee6da5b05c5a3f0a90157ac9a9c9a5a2d2367af0cacd44f92e01a2369c1bd7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
92b930fb-3ef3-4b31-9b27-9297cc1f9d6f
Mapping establishedEvidence supported

vendor-613dd4bb79ad8759a10407fe624cb651bdb422f3f2780231736f064b614ee756 · product-5dde4c9cb73aecdcebabe94977fd047e4f6d666c43d098158c9e7086fbdcf9c3

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
20b6981c-4f3d-432a-9d61-9c9ad85af66e7ac7b0be-1ee3-4944-bf13-8bcd8551de199d4a85e1-325c-4aef-af15-f5e01f408b32
Mapping establishedEvidence supported

vendor-613dd4bb79ad8759a10407fe624cb651bdb422f3f2780231736f064b614ee756 · product-74f89a03a794cfd5616f30fe592f30eb465dda6c915da7e76ed8b8c72bac689b

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3cc876a8-9eea-4c0b-ab84-a78f3ecb1e2a3d4dd64b-4003-484a-9452-fdac72b6bed36eab1789-05cf-48e0-8c47-83484418961bd3ed945e-b28d-4168-807c-d89a0d56f44fda95be4a-bd35-4883-b852-2d7c3f349706
Mapping establishedEvidence supported

vendor-613dd4bb79ad8759a10407fe624cb651bdb422f3f2780231736f064b614ee756 · product-829994e2b3ac7aea9e17116454437c3851ed8a99c09dcfe4202719f57a4c29a9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f4a46ea4-1970-42ce-b21d-bc7b833fa35b
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4b939e09-e157-47f4-990c-ef47691bcb64

Assessments

CVSS by origin

6.5
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
4.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:S/C:P/I:N/A:N
6.5
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Direct CVE/CNA normalized decisions

6.5Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Validation
Valid match
Recomputed
6.5
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.