Junglewise Threat Intelligence

CVE-2019-12991: Citrix SD-WAN and NetScaler Command Injection Vulnerability

CVE-2019-12991 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-25

Technologies: Cisco SD-WAN, Citrix NetScaler. Vendors: Citrix, Cisco.

Executive brief

Citrix SD-WAN and NetScaler SD-WAN appliances are vulnerable to authenticated OS command injection due to improper input validation. An authenticated attacker can exploit this vulnerability to execute arbitrary commands on the underlying operating system.

Affected products

  • Citrix SD-WAN 10.2.x before 10.2.3
  • Citrix NetScaler SD-WAN 10.0.x before 10.0.8

Timeline

  • 2019-07-16: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats