Junglewise Threat Intelligence

CVE-2019-19781: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

CVE-2019-19781 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Citrix Sd-Wan Wanop Appliance, Citrix Application Delivery Controller (ADC), Citrix Gateway. Vendors: Citrix.

Executive brief

Citrix ADC, Gateway, and SD-WAN WANOP appliances are vulnerable to a directory traversal flaw. An unauthenticated remote attacker can exploit this to perform arbitrary code execution on the affected system.

Affected products

  • Citrix Application Delivery Controller (ADC) 10.5, 11.1, 12.0, 12.1, 13.0
  • Citrix Gateway 10.5, 11.1, 12.0, 12.1, 13.0
  • Citrix SD-WAN WANOP

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats