Record summary

CVE-2019-12990 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALCitrix SD-WAN Center - Local File InclusionCVSS 9.8

Citrix SD-WAN Center is susceptible to local file inclusion via the applianceSettingsFileTransfer function in ApplianceSettingsController. The function does not sufficiently validate or sanitize HTTP request parameter values used to construct a file system path. An attacker can trigger this vulnerability by routing traffic through the Collector controller and supplying a crafted value for filename, filedata, and workspace_id, therefore being able to write files to locations writable by the www-data user and/or to write a crafted PHP file to /home/talariuser/www/app/webroot/files/ to execute arbitrary PHP code.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, remote code execution, or denial of service.

Remediation

Apply the latest security patches or updates provided by Citrix to mitigate the vulnerability.

WeaknessesCWE-22
Authorsgy741
Template tagscvecve2019citrixrceunauthtenableintrusivevkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:*
Shodan: http.title:"Citrix SD-WAN"
Shodan: http.title:"citrix sd-wan"
FOFA: title="citrix sd-wan"
Google: intitle:"citrix sd-wan"

Source: ProjectDiscovery

References

5