CVE-2019-12990
Citrix SD-WAN and NetScaler Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2019-12990 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 26, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SD-WAN and NetScalerBrowse Citrix / SD-WAN and NetScaler | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALCitrix SD-WAN Center - Local File InclusionCVSS 9.8
Citrix SD-WAN Center is susceptible to local file inclusion via the applianceSettingsFileTransfer function in ApplianceSettingsController. The function does not sufficiently validate or sanitize HTTP request parameter values used to construct a file system path. An attacker can trigger this vulnerability by routing traffic through the Collector controller and supplying a crafted value for filename, filedata, and workspace_id, therefore being able to write files to locations writable by the www-data user and/or to write a crafted PHP file to /home/talariuser/www/app/webroot/files/ to execute arbitrary PHP code.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, remote code execution, or denial of service.
Remediation
Apply the latest security patches or updates provided by Citrix to mitigate the vulnerability.
Source: ProjectDiscovery