CVE-2019-12989
KEV PoC ×2largeUnauthenticated SQL Injection in Citrix SD-WAN and NetScaler SD-WAN
CISA: Citrix SD-WAN and NetScaler SQL Injection Vulnerability
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 contain a SQL injection flaw (CWE-89) in the appliance software. The CVSS vector shows it is exploitable remotely by an unauthenticated attacker with no user interaction, by sending crafted requests to the affected product. Successful SQL injection carries high impact across confidentiality, integrity, and availability, and public research (Tenable TRA-2019-32 and a public PacketStorm PoC against version 10.2.2) demonstrates it can be leveraged for authentication bypass leading to remote command execution. Organizations running the affected Citrix/NetScaler SD-WAN versions, especially those with appliance management interfaces reachable from untrusted networks, are exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 and carries a 94% EPSS probability of exploitation within 30 days, indicating active or highly likely exploitation in the wild.
What to do: Upgrade Citrix SD-WAN 10.2.x appliances to 10.2.3 or later and NetScaler SD-WAN 10.0.x appliances to 10.0.8 or later, per the vendor's instructions. Restrict appliance management interfaces to trusted networks or VPN access and review appliance logs for signs of compromise, since the flaw is on CISA's KEV list. Organizations that cannot patch immediately should minimize exposure of the management UI to the internet.
| Citrix SD-WAN | 10.2.x before 10.2.3 |
| Citrix NetScaler SD-WAN | 10.0.x before 10.0.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
- Affected
- Citrix SD-WAN and NetScaler
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- netscaler sd-wan, sd-wan
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.