Record summary

CVE-2019-12988 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 31, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALCitrix SD-WAN Center - Remote Command InjectionCVSS 9.8

Citrix SD-WAN Center is susceptible to remote command injection via the addModifyZTDProxy function in NmsController. The function does not sufficiently validate or sanitize HTTP request parameter values that are used to construct a shell command. An attacker can trigger this vulnerability by routing traffic through the Collector controller and supplying a crafted value for ztd_password, thereby potentially being able to obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data exfiltration, and potential compromise of the entire SD-WAN infrastructure.

Remediation

Apply the latest security patches provided by Citrix to mitigate the vulnerability.

WeaknessesCWE-78
Authorsgy741
Template tagscvecve2019rceunauthoasttenablecitrixvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:*
Shodan: http.title:"Citrix SD-WAN"
Shodan: http.title:"citrix sd-wan"
FOFA: title="citrix sd-wan"
Google: intitle:"citrix sd-wan"

Source: ProjectDiscovery

References

4