CVE-2019-12991
KEV PoC ×2largeAuthenticated Command Injection in Citrix SD-WAN and NetScaler SD-WAN
CISA: Citrix SD-WAN and NetScaler Command Injection Vulnerability
CVE-2019-12991 is an operating system command injection flaw (CWE-78) caused by improper input validation in the management interface of Citrix SD-WAN and NetScaler SD-WAN appliances. A remote attacker who holds low-privileged credentials on the appliance's management interface can send crafted input that gets executed as OS commands, yielding full command execution with high impact on confidentiality, integrity, and availability. Public exploit references, including a PoC that combines an authentication bypass with remote command execution on a Citrix SD-WAN Appliance 10.2.2, demonstrate the practical attack path against these appliances. Administrators running Citrix SD-WAN 10.2.x prior to 10.2.3 or NetScaler SD-WAN 10.0.x prior to 10.0.8 are affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25, required action: apply updates per vendor instructions), and its 74.1% EPSS probability indicates a high likelihood of exploitation, so exploitation in the wild should be assumed.
What to do: Upgrade Citrix SD-WAN 10.2.x deployments to 10.2.3 (or later) and NetScaler SD-WAN 10.0.x deployments to 10.0.8 (or later) per vendor instructions. Restrict the appliance management interface to trusted management networks rather than the public internet, and review management-interface access logs for signs of authentication bypass or unauthorized command execution. Inventory all appliances on the 10.2.x and 10.0.x branches, since this flaw is listed in CISA's KEV catalog and rapid patching is required.
| Citrix SD-WAN | 10.2.x before 10.2.3 |
| Citrix NetScaler SD-WAN | 10.0.x before 10.0.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
- Affected
- Citrix SD-WAN and NetScaler
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- netscaler sd-wan, sd-wan
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.