CVE-2019-19781
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
31
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Se descubrió un problema en Citrix Application Delivery Controller (ADC) and Gateway versiones 10.5, 11.1, 12.0, 12.1 y 13.0. Permiten un salto de directorio.
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-12-13 CVE Reserved
- 2019-12-27 CVE Published
- 2020-01-11 First Exploit
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-11-01 EPSS Updated
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (43)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.citrix.com/article/CTX267027 | 2023-01-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | 10.5 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version "10.5" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | 11.1 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version "11.1" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | 12.0 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version "12.0" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | 12.1 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version "12.1" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Application Delivery Controller Firmware Search vendor "Citrix" for product "Application Delivery Controller Firmware" | 13.0 Search vendor "Citrix" for product "Application Delivery Controller Firmware" and version "13.0" | - |
Affected
| in | Citrix Search vendor "Citrix" | Application Delivery Controller Search vendor "Citrix" for product "Application Delivery Controller" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | 10.5 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version "10.5" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | 11.1 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version "11.1" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | 12.0 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version "12.0" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Netscaler Gateway Firmware Search vendor "Citrix" for product "Netscaler Gateway Firmware" | 12.1 Search vendor "Citrix" for product "Netscaler Gateway Firmware" and version "12.1" | - |
Affected
| in | Citrix Search vendor "Citrix" | Netscaler Gateway Search vendor "Citrix" for product "Netscaler Gateway" | - | - |
Safe
|
Citrix Search vendor "Citrix" | Gateway Firmware Search vendor "Citrix" for product "Gateway Firmware" | 13.0 Search vendor "Citrix" for product "Gateway Firmware" and version "13.0" | - |
Affected
| in | Citrix Search vendor "Citrix" | Gateway Search vendor "Citrix" for product "Gateway" | - | - |
Safe
|