CVE-2020-10112
Last modified
CVE-2020-10112 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Gateway Firmware | 11.1 |
| Citrix | Gateway Firmware | 12.0 |
| Citrix | Gateway Firmware | 12.1 |
References
- http://seclists.org/fulldisclosure/2020/Mar/8Exploit, Mailing List, Third Party Advisory
- https://support.citrix.com/searchVendor Advisory
- http://seclists.org/fulldisclosure/2020/Mar/8Exploit, Mailing List, Third Party Advisory
- https://support.citrix.com/searchVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10112?
How severe is CVE-2020-10112?
How do I fix CVE-2020-10112?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10107PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to…5.4
- CVE-2020-10108In Twisted Web through 19.10.0, there was an HTTP request sp…9.8
- CVE-2020-10109In Twisted Web through 19.10.0, there was an HTTP request sp…9.8
- CVE-2020-1011An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-10110Citrix Gateway 11.1, 12.0, and 12.1 allows Information Expos…5.3
- CVE-2020-10111Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Inte…7.5
- CVE-2020-10113cPanel before 84.0.20 allows self XSS via a temporary charac…6.1
- CVE-2020-10114cPanel before 84.0.20 allows stored self-XSS via the HTML fi…6.1
- CVE-2020-10115cPanel before 84.0.20, when PowerDNS is used, allows arbitra…7.2
- CVE-2020-10116cPanel before 84.0.20 allows attackers to bypass intended re…5.3
- CVE-2020-10117cPanel before 84.0.20 mishandles enforcement of demo checks …9.1
- CVE-2020-10118cPanel before 84.0.20 allows a demo account to modify files …9.1
Are you affected by CVE-2020-10112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
