CVE-2019-19781

CRITICAL KEV RANSOMWARE NUCLEI

Citrix ADC (NetScaler) Directory Traversal Scanner

Title source: metasploit

Description

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Exploits (55)

exploitdb SCANNER
by Dhiraj Mishra · textwebappsmultiple
https://www.exploit-db.com/exploits/47930
exploitdb WORKING POC
by mekhalleh · rubywebappsmultiple
https://www.exploit-db.com/exploits/47913
exploitdb WORKING POC
by Project Zero India · bashwebappsmultiple
https://www.exploit-db.com/exploits/47901
nomisec WORKING POC 576 stars
by trustedsec · remote
https://github.com/trustedsec/cve-2019-19781
nomisec WORKING POC 370 stars
by projectzeroindia · remote
https://github.com/projectzeroindia/CVE-2019-19781
nomisec WORKING POC 159 stars
by mpgn · remote
https://github.com/mpgn/CVE-2019-19781
nomisec SCANNER 118 stars
by MalwareTech · poc
https://github.com/MalwareTech/CitrixHoneypot
nomisec SCANNER 109 stars
by cisagov · infoleak
https://github.com/cisagov/check-cve-2019-19781
nomisec SCANNER 94 stars
by mandiant · poc
https://github.com/mandiant/ioc-scanner-CVE-2019-19781
nomisec WORKING POC 84 stars
by jas502n · remote
https://github.com/jas502n/CVE-2019-19781
nomisec SCANNER 58 stars
by citrix · poc
https://github.com/citrix/ioc-scanner-CVE-2019-19781
nomisec SCANNER 11 stars
by aqhmal · infoleak
https://github.com/aqhmal/CVE-2019-19781
nomisec WORKING POC 10 stars
by w4fz5uck5 · remote
https://github.com/w4fz5uck5/CVE-2019-19781-CitrixRCE
nomisec WORKING POC 7 stars
by VladRico · remote
https://github.com/VladRico/CVE-2019-19781
nomisec WORKING POC 7 stars
by ianxtianxt · remote
https://github.com/ianxtianxt/CVE-2019-19781
nomisec SCANNER 4 stars
by onSec-fr · poc
https://github.com/onSec-fr/CVE-2019-19781-Forensic
nomisec WORKING POC 4 stars
by unknowndevice64 · poc
https://github.com/unknowndevice64/Exploits_CVE-2019-19781
nomisec SUSPICIOUS 3 stars
by k-fire · poc
https://github.com/k-fire/CVE-2019-19781-exploit
nomisec SCANNER 3 stars
by j81blog · poc
https://github.com/j81blog/ADC-19781
nomisec SCANNER 2 stars
by DanielWep · poc
https://github.com/DanielWep/CVE-NetScalerFileSystemCheck
nomisec SCANNER 2 stars
by andripwn · infoleak
https://github.com/andripwn/CVE-2019-19781
nomisec WORKING POC 2 stars
by oways · infoleak
https://github.com/oways/CVE-2019-19781
gitlab SCANNER 1 stars
by bontchev · poc
https://gitlab.com/bontchev/CitrixHoneypot
nomisec SUSPICIOUS 1 stars
by Vulnmachines · infoleak
https://github.com/Vulnmachines/Ctirix_RCE-CVE-2019-19781
nomisec SCANNER 1 stars
by nmanzi · infoleak
https://github.com/nmanzi/webcvescanner
nomisec WORKING POC 1 stars
by r4ulcl · poc
https://github.com/r4ulcl/CVE-2019-19781
nomisec SCANNER 1 stars
by redscan · poc
https://github.com/redscan/CVE-2019-19781
nomisec SCANNER
by autocode07 · poc
https://github.com/autocode07/cisagov__check-cve-2019-19781.4142e02b
nomisec WORKING POC
by tpdlshdmlrkfmcla · poc
https://github.com/tpdlshdmlrkfmcla/CVE-2019-19781
nomisec WRITEUP
by zerobytesecure · remote
https://github.com/zerobytesecure/CVE-2019-19781
nomisec WRITEUP
by Azeemering · poc
https://github.com/Azeemering/CVE-2019-19781-DFIR-Notes
nomisec SCANNER
by pwn3z · infoleak
https://github.com/pwn3z/CVE-2019-19781-Citrix
nomisec WORKING POC
by jamesjguthrie · remote
https://github.com/jamesjguthrie/Shitrix-CVE-2019-19781
nomisec WORKING POC
by qiong-qi · remote
https://github.com/qiong-qi/CVE-2019-19781-poc
nomisec WORKING POC
by SharpHack · poc
https://github.com/SharpHack/CVE-2019-19781
nomisec SCANNER
by yukar1z0e · remote
https://github.com/yukar1z0e/CVE-2019-19781
nomisec WRITEUP
by L4r1k · poc
https://github.com/L4r1k/CitrixNetscalerAnalysis
nomisec SCANNER
by 0xams · poc
https://github.com/0xams/citrixvulncheck
nomisec SCANNER
by EliusHHimel · poc
https://github.com/EliusHHimel/citrix-honeypot
nomisec SCANNER
by digitalgangst · poc
https://github.com/digitalgangst/massCitrix
nomisec WORKING POC
by mekhalleh · remote
https://github.com/mekhalleh/citrix_dir_traversal_rce
nomisec SCANNER
by b510 · remote
https://github.com/b510/CVE-2019-19781
nomisec SCANNER
by Castaldio86 · poc
https://github.com/Castaldio86/Detect-CVE-2019-19781
nomisec SCANNER
by awesome-security · poc
https://github.com/awesome-security/citrixmash_scanner
nomisec WRITEUP
by digitalshadows · poc
https://github.com/digitalshadows/CVE-2019-19781_IOCs
nomisec SUSPICIOUS
by zgelici · poc
https://github.com/zgelici/CVE-2019-19781-Checker
nomisec WORKING POC
by hollerith · remote
https://github.com/hollerith/CVE-2019-19781
nomisec NO CODE
by becrevex · infoleak
https://github.com/becrevex/Citrix_CVE-2019-19781
vulncheck_xdb WORKING POC
infoleak
https://github.com/user20252228/CVE-2019-19781
metasploit SCANNER
by Mikhail Klyuchnikov, Erik Wynter, altonjx · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/citrix_dir_traversal.rb
metasploit WORKING POC EXCELLENT
by Mikhail Klyuchnikov, Project Zero India, TrustedSec, James Brytan, James Smith, Marisa Mack, Rob Vinson, Sergey Pashevkin, Steven Laura, mekhalleh (RAMELLA Sébastien) · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/freebsd/http/citrix_dir_traversal_rce.rb

Nuclei Templates (1)

Citrix ADC and Gateway - Directory Traversal
CRITICALby organiccrap,geeknik

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-01-16
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-9380
Ransomware Use Confirmed
CWE
CWE-22
Status published
Products (10)
citrix/application_delivery_controller_firmware 10.5
citrix/application_delivery_controller_firmware 11.1
citrix/application_delivery_controller_firmware 12.0
citrix/application_delivery_controller_firmware 12.1
citrix/application_delivery_controller_firmware 13.0
citrix/gateway_firmware 13.0
citrix/netscaler_gateway_firmware 10.5
citrix/netscaler_gateway_firmware 11.1
citrix/netscaler_gateway_firmware 12.0
citrix/netscaler_gateway_firmware 12.1
Published Dec 27, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026