CVE-2019-19781
citrix application delivery controller firmware, citrix netscaler gateway firmware, citrix gateway firmware
Published 27 Dec 2019 · updated 12 Aug 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
References
- packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html · Third Party Advisory, VDB Entry
- badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/ · Broken Link, Third Party Advisory
- forms.gle/eDf3DXZAv96oosfj6 · Third Party Advisory
- support.citrix.com/article/CTX267027 · Vendor Advisory
- twitter.com/bad_packets/status/1215431625766424576 · Broken Link, Third Party Advisory
- www.kb.cert.org/vuls/id/619785 · Third Party Advisory, US Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19781 · US Government Resource