CVE-2019-12987: OS Command Injection
Published Jul 16, 2019
·Updated
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
Affected Software
2 affected components
Citrix NetScaler SD-WAN>=10.0<10.0.8
Citrix SD-WAN>=10.2<10.2.3
Event History
Jul 16, 2019
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12987?
CVE-2019-12987 is a vulnerability in Citrix SD-WAN and NetScaler SD-WAN that allows improper input validation.
2
What is the severity of CVE-2019-12987?
The severity of CVE-2019-12987 is classified as critical with a severity value of 9.8.
3
Which software versions are affected by CVE-2019-12987?
Citrix SD-WAN versions between 10.2 and 10.2.3, and NetScaler SD-WAN versions between 10.0 and 10.0.8 are affected by CVE-2019-12987.
4
How can I fix CVE-2019-12987?
To fix CVE-2019-12987, update your Citrix SD-WAN software to version 10.2.3 or later, and NetScaler SD-WAN software to version 10.0.8 or later.
5
Where can I find more information about CVE-2019-12987?
You can find more information about CVE-2019-12987 on the following websites: securityfocus.com, support.citrix.com, and tenable.com.