CVE-2019-12988: OS Command Injection
Published Jul 16, 2019
·Updated
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).
Affected Software
2 affected components
Citrix NetScaler SD-WAN>=10.0<10.0.8
Citrix SD-WAN>=10.2<10.2.3
Event History
Jul 16, 2019
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Citrix vulnerability?
The vulnerability ID is CVE-2019-12988.
2
What is the severity of CVE-2019-12988?
The severity of CVE-2019-12988 is critical with a severity value of 9.8.
3
Which software versions are affected by CVE-2019-12988?
Citrix SD-WAN versions 10.2.x before 10.2.3 and NetScaler SD-WAN versions 10.0.x before 10.0.8 are affected by CVE-2019-12988.
4
What is the issue described by CVE-2019-12988?
CVE-2019-12988 is an improper input validation issue.
5
How can I fix CVE-2019-12988?
To fix CVE-2019-12988, it is recommended to upgrade Citrix SD-WAN to version 10.2.3 or higher, and NetScaler SD-WAN to version 10.0.8 or higher.