6.1

CVE-2020-8191

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

Data is provided by the National Vulnerability Database (NVD)
CitrixApplication Delivery Controller Firmware Version >= 10.5 < 10.5-70.18
CitrixApplication Delivery Controller Firmware Version >= 11.1 < 11.1-64.14
CitrixApplication Delivery Controller Firmware Version >= 12.0 < 12.0-63.21
CitrixApplication Delivery Controller Firmware Version >= 12.1 < 12.1-57.18
CitrixApplication Delivery Controller Firmware Version >= 13.0 < 13.0-58.30
CitrixNetscaler Gateway Firmware Version >= 10.5 < 10.5-70.18
   CitrixNetScaler Gateway Version-
CitrixNetscaler Gateway Firmware Version >= 11.1 < 11.1-64.14
   CitrixNetScaler Gateway Version-
CitrixNetscaler Gateway Firmware Version >= 12.0 < 12.0-63.21
   CitrixNetScaler Gateway Version-
CitrixNetscaler Gateway Firmware Version >= 12.1 < 12.1-57.18
   CitrixNetScaler Gateway Version-
CitrixGateway Firmware Version >= 13.0 < 13.0-58.30
   CitrixGateway Version-
CitrixSd-wan Wanop Version >= 10.2 < 10.2.7
   Citrix4000-wo Version-
   Citrix4100-wo Version-
   Citrix5000-wo Version-
   Citrix5100-wo Version-
CitrixSd-wan Wanop Version >= 11.0 < 11.0.3d
   Citrix4000-wo Version-
   Citrix4100-wo Version-
   Citrix5000-wo Version-
   Citrix5100-wo Version-
CitrixSd-wan Wanop Version >= 11.1 < 11.1.1a
   Citrix4000-wo Version-
   Citrix4100-wo Version-
   Citrix5000-wo Version-
   Citrix5100-wo Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 90.01% 0.996
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.