CVE-2019-12991: Citrix SD-WAN and NetScaler Command Injection Vulnerability
Published Jul 16, 2019
·Updated
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
Other sources
Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
— CISA
Affected Software
5 affected components
Citrix SD-WAN and NetScaler
Citrix NetScaler SD-WAN>=10.0<10.0.8
Citrix SD-WAN>=10.2<10.2.3
Citrix NetScaler SD-WAN>=10.0.0<10.0.8
Citrix SD-WAN>=10.2.0<10.2.3
Event History
Jul 16, 2019
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2022
Known Exploited
via CISA·12:00 AM
Jun 5, 58462
Event
via NVD·01:20 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Citrix SD-WAN and NetScaler vulnerability?
The vulnerability ID for this Citrix SD-WAN and NetScaler vulnerability is CVE-2019-12991.
2
What is the severity of CVE-2019-12991?
The severity of CVE-2019-12991 is critical, with a severity value of 8.8.
3
What is the affected software for this vulnerability?
The affected software for CVE-2019-12991 includes Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8.
4
What is the description of CVE-2019-12991?
CVE-2019-12991 is a command injection vulnerability in Citrix SD-WAN and NetScaler, caused by improper input validation.
5
How can I fix the vulnerability CVE-2019-12991?
To fix CVE-2019-12991, you should update Citrix SD-WAN to version 10.2.3 or NetScaler SD-WAN to version 10.0.8.