CVE-2019-12985: OS Command Injection
Published Jul 16, 2019
·Updated
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
Affected Software
2 affected components
Citrix NetScaler SD-WAN>=10.0<10.0.8
Citrix SD-WAN>=10.2<10.2.3
Event History
Jul 16, 2019
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-12985.
2
What is the severity of CVE-2019-12985?
The severity of CVE-2019-12985 is critical with a score of 9.8.
3
Which software versions are affected by CVE-2019-12985?
Citrix SD-WAN versions between 10.2 and 10.2.3, and NetScaler SD-WAN versions between 10.0 and 10.0.8 are affected by CVE-2019-12985.
4
What is the impact of CVE-2019-12985?
CVE-2019-12985 can be exploited to allow remote code execution and unauthorized access.
5
How can I mitigate CVE-2019-12985?
To mitigate CVE-2019-12985, it is recommended to upgrade to Citrix SD-WAN version 10.2.3 or later, and NetScaler SD-WAN version 10.0.8 or later.