Citrix
Citrix Gateway Firmware: vulnerabilidades y CVE
Citrix Gateway Firmware tiene 15 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses1
Críticas4
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-27518 | Crítica (9.8) | 6.7% | ⚠ Explotación activa | 13 dic 2022 | Unauthenticated remote arbitrary code execution |
| CVE-2019-19781 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 dic 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. |
| CVE-2020-8195 | Media (6.5) | 33% | ⚠ Explotación activa | 10 jul 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in… |
| CVE-2020-8196 | Media (4.3) | 26% | ⚠ Explotación activa | 10 jul 2020 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in… |
| CVE-2020-8193 | Media (6.5) | 88% | ⚠ Explotación activa | 10 jul 2020 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75160 | Crítica (9.1) | 0.60% | — | 4 sept 2026 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. |
| CVE-2022-27518 | Crítica (9.8) | 6.7% | ⚠ Explotación activa | 13 dic 2022 | Unauthenticated remote arbitrary code execution |
| CVE-2020-8198 | Media (6.1) | 0.97% | — | 10 jul 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in… |
| CVE-2020-8197 | Alta (8.8) | 1.8% | — | 10 jul 2020 | Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary… |
| CVE-2020-8196 | Media (4.3) | 26% | ⚠ Explotación activa | 10 jul 2020 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in… |
| CVE-2020-8195 | Media (6.5) | 33% | ⚠ Explotación activa | 10 jul 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in… |
| CVE-2020-8194 | Media (6.5) | 11% | — | 10 jul 2020 | Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the… |
| CVE-2020-8193 | Media (6.5) | 88% | ⚠ Explotación activa | 10 jul 2020 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows… |
| CVE-2020-8191 | Media (6.1) | 26% | — | 10 jul 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows… |
| CVE-2020-8190 | Alta (7.5) | 1.2% | — | 10 jul 2020 | Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation. |
| CVE-2020-10112 | Media (5.4) | 1.5% | — | 6 mar 2020 | Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage.… |
| CVE-2020-10111 | Alta (7.5) | 2.0% | — | 6 mar 2020 | Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance… |
| CVE-2020-10110 | Media (5.3) | 2.7% | — | 6 mar 2020 | Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC.… |
| CVE-2019-19781 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 dic 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. |
| CVE-2019-18225 | Crítica (9.8) | 1.5% | — | 21 oct 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
📰 Noticias relacionadas
Otros productos de Citrix
Xenserver · 55Netscaler Gateway · 45Netscaler Application Delivery Controller · 39Netscaler Gateway Firmware · 31Application Delivery Controller Firmware · 30Netscaler Application Delivery Controller Firmware · 29Xenmobile Server · 22Gateway · 19Sd-wan · 18Netscaler Sd-wan · 16Workspace · 14Access Gateway · 14