ZeroHour

CVE-2019-12991

KEV PoC ×2large

Authenticated Command Injection in Citrix SD-WAN and NetScaler SD-WAN

CISA: Citrix SD-WAN and NetScaler Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
74%p99
Published
()
KEV added
AI analysis

CVE-2019-12991 is an operating system command injection flaw (CWE-78) caused by improper input validation in the management interface of Citrix SD-WAN and NetScaler SD-WAN appliances. A remote attacker who holds low-privileged credentials on the appliance's management interface can send crafted input that gets executed as OS commands, yielding full command execution with high impact on confidentiality, integrity, and availability. Public exploit references, including a PoC that combines an authentication bypass with remote command execution on a Citrix SD-WAN Appliance 10.2.2, demonstrate the practical attack path against these appliances. Administrators running Citrix SD-WAN 10.2.x prior to 10.2.3 or NetScaler SD-WAN 10.0.x prior to 10.0.8 are affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25, required action: apply updates per vendor instructions), and its 74.1% EPSS probability indicates a high likelihood of exploitation, so exploitation in the wild should be assumed.

What to do: Upgrade Citrix SD-WAN 10.2.x deployments to 10.2.3 (or later) and NetScaler SD-WAN 10.0.x deployments to 10.0.8 (or later) per vendor instructions. Restrict the appliance management interface to trusted management networks rather than the public internet, and review management-interface access logs for signs of authentication bypass or unauthorized command execution. Inventory all appliances on the 10.2.x and 10.0.x branches, since this flaw is listed in CISA's KEV catalog and rapid patching is required.

Affected
Citrix SD-WAN10.2.x before 10.2.3
Citrix NetScaler SD-WAN10.0.x before 10.0.8
Estimated exposure
largetens of thousands of appliances across thousands of enterprise branch-office deployments (estimate) — These are enterprise SD-WAN edge appliances typically deployed in multiples per customer branch site, and public internet scans of exposed SD-WAN management interfaces support an order of magnitude in the tens of thousands of devices; this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

CISA Known Exploited Vulnerability
Affected
Citrix SD-WAN and NetScaler
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
netscaler sd-wan, sd-wan
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.