ZeroHour

CVE-2019-12989

KEV PoC ×2large

Unauthenticated SQL Injection in Citrix SD-WAN and NetScaler SD-WAN

CISA: Citrix SD-WAN and NetScaler SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
94%p100
Published
()
KEV added
AI analysis

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 contain a SQL injection flaw (CWE-89) in the appliance software. The CVSS vector shows it is exploitable remotely by an unauthenticated attacker with no user interaction, by sending crafted requests to the affected product. Successful SQL injection carries high impact across confidentiality, integrity, and availability, and public research (Tenable TRA-2019-32 and a public PacketStorm PoC against version 10.2.2) demonstrates it can be leveraged for authentication bypass leading to remote command execution. Organizations running the affected Citrix/NetScaler SD-WAN versions, especially those with appliance management interfaces reachable from untrusted networks, are exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 and carries a 94% EPSS probability of exploitation within 30 days, indicating active or highly likely exploitation in the wild.

What to do: Upgrade Citrix SD-WAN 10.2.x appliances to 10.2.3 or later and NetScaler SD-WAN 10.0.x appliances to 10.0.8 or later, per the vendor's instructions. Restrict appliance management interfaces to trusted networks or VPN access and review appliance logs for signs of compromise, since the flaw is on CISA's KEV list. Organizations that cannot patch immediately should minimize exposure of the management UI to the internet.

Affected
Citrix SD-WAN10.2.x before 10.2.3
Citrix NetScaler SD-WAN10.0.x before 10.0.8
Estimated exposure
largetens of thousands of internet-exposed appliances; total deployed base plausibly 100,000+ branch devices — SD-WAN appliances are deployed per branch site across Citrix's large enterprise customer base, public internet scans have long shown thousands of exposed SD-WAN management interfaces, and the March 2022 KEV listing corroborates broad…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

CISA Known Exploited Vulnerability
Affected
Citrix SD-WAN and NetScaler
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
netscaler sd-wan, sd-wan
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.