First published: Tue Jul 16 2019(Updated: )
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler SD-WAN | >=10.0<10.0.8 | |
Citrix SD-WAN | >=10.2<10.2.3 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Citrix SD-WAN and NetScaler vulnerability is CVE-2019-12991.
The severity of CVE-2019-12991 is critical, with a severity value of 8.8.
The affected software for CVE-2019-12991 includes Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8.
CVE-2019-12991 is a command injection vulnerability in Citrix SD-WAN and NetScaler, caused by improper input validation.
To fix CVE-2019-12991, you should update Citrix SD-WAN to version 10.2.3 or NetScaler SD-WAN to version 10.0.8.