PT-2020-11933 · Citrix · Citrix Gateway+1

Micha Borrmann

·

Published

2020-03-06

·

Updated

2024-08-04

·

CVE-2020-10111

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Citrix Gateway versions 11.1 through 12.1
Description The issue concerns an Inconsistent Interpretation of HTTP Requests. It is noted that Citrix disputes the reported behavior as not a security issue, stating that Citrix ADC only caches HTTP/1.1 traffic for performance optimization.
Recommendations For Citrix Gateway versions 11.1 through 12.1, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2020-10111

Affected Products

Citrix Adc
Citrix Gateway