CVE-2019-19781: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Other sources
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19781?
CVE-2019-19781 is a code execution vulnerability in Citrix ADC Gateway and SD-WAN WANOP Appliance.
How severe is CVE-2019-19781?
CVE-2019-19781 has a severity rating of 9.8, which is considered critical.
Which Citrix products are affected by CVE-2019-19781?
Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance firmware versions 10.5, 11.1, 12.0, 12.1, and 13.0 are affected.
How can an attacker exploit CVE-2019-19781?
An unauthenticated attacker can exploit CVE-2019-19781 to perform code execution.
Where can I find more information about CVE-2019-19781?
You can find more information about CVE-2019-19781 at the following references: [link1](http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html), [link2](http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.html), [link3](http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.html).