CVE-2019-12992: OS Command Injection
Published Jul 16, 2019
·Updated
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).
Affected Software
2 affected components
Citrix NetScaler SD-WAN>=10.0<10.0.8
Citrix SD-WAN>=10.2<10.2.3
Event History
Jul 16, 2019
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12992?
CVE-2019-12992 is a vulnerability in Citrix SD-WAN and NetScaler SD-WAN that allows improper input validation.
2
What is the severity of CVE-2019-12992?
CVE-2019-12992 has a severity rating of 8.8, which is classified as critical.
3
How does CVE-2019-12992 affect Citrix SD-WAN and NetScaler SD-WAN?
CVE-2019-12992 affects Citrix SD-WAN versions 10.2.x before 10.2.3 and NetScaler SD-WAN versions 10.0.x before 10.0.8.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-12992?
CVE-2019-12992 is associated with CWE-20 (Improper Input Validation) and CWE-78 (Improper Neutralization of Special Elements Used in an OS Command).
5
How can I fix the CVE-2019-12992 vulnerability?
To fix CVE-2019-12992, it is recommended to update Citrix SD-WAN to version 10.2.3 or later and NetScaler SD-WAN to version 10.0.8 or later.