CVE-2020-8190
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2020-8190 is a local privilege escalation vulnerability affecting Citrix ADC and Citrix Gateway products before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18. The vulnerability was discovered and disclosed in July 2020, requiring an authenticated user on the NSIP (NetScaler IP) interface for exploitation (Citrix Blog).

Technical details

The vulnerability stems from incorrect file permissions in the affected Citrix products. This issue cannot be exploited directly, as an attacker must first obtain 'nobody' privileges using another exploit before leveraging this vulnerability (Citrix Blog).

Impact

The vulnerability allows for local privilege escalation if successfully exploited. However, the impact is limited by the requirement of pre-existing access and the need to chain with another exploit to achieve elevation of privileges (Citrix Blog).

Exploitability

The exploitability of this vulnerability is considered limited due to multiple prerequisites. An attacker must first have authenticated access to the NSIP interface and must already have obtained 'nobody' privileges through a separate exploit. At the time of disclosure, Citrix confirmed there were no known exploits in the wild (Citrix Blog).

Mitigation and workarounds

Citrix has released patches to address this vulnerability in versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18. Organizations are strongly recommended to apply these patches to affected systems. The Citrix-managed Gateway service is not affected by this vulnerability (Citrix Blog).

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management