Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
Critical CVSS 9.8 Listed in CISA KEV
Summary
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Citrix:Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
CH-4 Twitter/X Fair-Use Reference
This reference follows the DR-006 + DR-008 fair-use boundary: ≤280-char verbatim quote, mandatory @attribution, mandatory outbound link. No account mirroring and no third-party tracker widget loaded.
Original author
Read tweet ↗ · Tweets may be deleted or accounts suspended; see the R2 archive if the original is unreachable.
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2019-19781 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html Third Party Advisory
- http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.html Third Party Advisory
- http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.html Third Party Advisory
- http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.html Third Party Advisory
- http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html Third Party Advisory
- https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/ Broken Link
- https://forms.gle/eDf3DXZAv96oosfj6 Third Party Advisory
- https://support.citrix.com/article/CTX267027 Vendor Advisory
- https://twitter.com/bad_packets/status/1215431625766424576 Broken Link
- https://www.kb.cert.org/vuls/id/619785 Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19781 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD