CVE-2019-12991
citrix netscaler sd-wan, citrix sd-wan
Published 16 Jul 2019 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
References
- packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html · Exploit, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/109133 · Broken Link, Third Party Advisory, VDB Entry
- support.citrix.com/article/CTX251987 · Vendor Advisory
- www.tenable.com/security/research/tra-2019-32 · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-12991 · US Government Resource