CVE-2019-19781
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-22
מוצרים מושפעים
citrix: application delivery controller firmware; citrix: application delivery controller; citrix: netscaler gateway firmware; citrix: netscaler gateway; citrix: gateway firmware; citrix: gateway
קישורים
- https://support.citrix.com/article/CTX267027 Vendor Advisory
- https://support.citrix.com/article/CTX267027 Vendor Advisory
- http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Contro… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Contro… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Contro… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Tra… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.… Third Party AdvisoryVDB Entry
- https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve… Broken LinkThird Party Advisory
- https://forms.gle/eDf3DXZAv96oosfj6 Third Party Advisory
- https://twitter.com/bad_packets/status/1215431625766424576 Broken LinkThird Party Advisory