
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical vulnerability (CVE-2019-19781) was discovered in Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0, allowing directory traversal and remote code execution by unauthenticated attackers. The vulnerability was disclosed on December 17, 2019, affecting multiple Citrix products including NetScaler ADC, NetScaler Gateway, and Citrix SD-WAN WANOP appliance models (CERT VU).
The vulnerability stems from the web server's failure to properly restrict access to Perl scripts available via the /vpns/ path. Attackers can exploit this by sending specially crafted requests containing directory traversal attempts (/../) to access the /vpns/ directory. The attack technique involves writing an XML file using directory traversal and subsequent command execution through the Perl Template Toolkit. The vulnerability received a CVSS v3.1 base score of 9.8 CRITICAL with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).
The exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems, potentially leading to complete system compromise. Over 25,000 Citrix NetScaler endpoints were identified as vulnerable during the initial discovery period (CERT VU).
The vulnerability is highly exploitable as it requires no authentication and can be triggered through specially crafted HTTP requests. Multiple proof-of-concept exploits were publicly released, and the vulnerability has been actively exploited in the wild. A simple test can be performed by accessing the path '/vpn/../vpns/cfg/smb.conf' on affected systems (CERT VU).
Citrix released permanent fixes for all supported versions and provided mitigation steps for systems that couldn't be immediately patched. The mitigation involves implementing responder policies to block requests containing directory traversal attempts and access to the /vpns/ directory. For standalone systems, specific commands were provided to implement these restrictions. Citrix strongly recommended applying the patches regardless of mitigation measures (Citrix Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."