VulnerabilityAnalyzed
CVE-2019-19781
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 100.0%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-22
- Affected
- citrix/application delivery controller firmware · citrix/netscaler gateway firmware · citrix/gateway firmware
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-19781
References
- http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.htmlThird Party Advisory, VDB Entry
- https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/Broken Link, Third Party Advisory
- https://forms.gle/eDf3DXZAv96oosfj6Third Party Advisory
- https://support.citrix.com/article/CTX267027Vendor Advisory
- https://twitter.com/bad_packets/status/1215431625766424576Broken Link, Third Party Advisory
- https://www.kb.cert.org/vuls/id/619785Third Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.htmlThird Party Advisory, VDB Entry
- https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/Broken Link, Third Party Advisory
- https://forms.gle/eDf3DXZAv96oosfj6Third Party Advisory
- https://support.citrix.com/article/CTX267027Vendor Advisory
- https://twitter.com/bad_packets/status/1215431625766424576Broken Link, Third Party Advisory
- https://www.kb.cert.org/vuls/id/619785Third Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19781US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.