// For flags

CVE-2020-10111

Citrix Gateway 11.1 / 12.0 / 12.1 Cache Bypass

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization

** EN DISPUTA ** Citrix Gateway 11.1, 12.0 y 12.1 tiene una interpretación inconsistente de las solicitudes HTTP. NOTA: Citrix cuestiona el comportamiento informado como un problema de seguridad. Citrix ADC solo almacena en caché el tráfico HTTP / 1.1 para la optimización del rendimiento.

Citrix Gateway versions 11.1, 12.0, and 12.1 suffer from a caching bypass vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-03-05 CVE Reserved
  • 2020-03-06 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Citrix
Search vendor "Citrix"
Gateway Firmware
Search vendor "Citrix" for product "Gateway Firmware"
11.1
Search vendor "Citrix" for product "Gateway Firmware" and version "11.1"
-
Affected
Citrix
Search vendor "Citrix"
Gateway Firmware
Search vendor "Citrix" for product "Gateway Firmware"
12.0
Search vendor "Citrix" for product "Gateway Firmware" and version "12.0"
-
Affected
Citrix
Search vendor "Citrix"
Gateway Firmware
Search vendor "Citrix" for product "Gateway Firmware"
12.1
Search vendor "Citrix" for product "Gateway Firmware" and version "12.1"
-
Affected