CVE-2020-10112: Citrix Gateway Firmware

Medium severity, CVSS 5.4. EPSS: 1.5% chance of exploitation in the next 30 days.

Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default

Affected products

  • Citrix Gateway Firmware: version 11.1 only; version 12.0 only; version 12.1 only

Published 2020-03-06. Last modified 2026-06-17.