CVE-2019-12991
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
Citrix SD-WAN and NetScaler SD-WAN versions before specific updates fail to properly validate user input, which can allow attackers to execute arbitrary commands on affected systems.
The vulnerability stems from improper input validation in Citrix SD-WAN 10.2.x (<10.2.3) and NetScaler SD-WAN 10.0.x (<10.0.8), enabling OS command injection (CWE-78). An attacker with network access to the vulnerable application can inject malicious input that bypasses validation filters, leading to unauthenticated remote code execution with system-level privileges.
The full analysis of this CVE is available in Portuguese →