CVE-2019-12991highunder attackCWE-78

CVE-2019-12991

Published · Updated

93Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 74%
from disclosure to weapon0 days
Published on NVDJul 16
1st PoCJul 12
CISA KEV+983d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

Citrix SD-WAN and NetScaler SD-WAN versions before specific updates fail to properly validate user input, which can allow attackers to execute arbitrary commands on affected systems.

Technical detail

The vulnerability stems from improper input validation in Citrix SD-WAN 10.2.x (<10.2.3) and NetScaler SD-WAN 10.0.x (<10.0.8), enabling OS command injection (CWE-78). An attacker with network access to the vulnerable application can inject malicious input that bypasses validation filters, leading to unauthenticated remote code execution with system-level privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.