CVE-2019-19781
Citrix ADC VPX vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2019-19781) was discovered in Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0, allowing directory traversal and remote code execution by unauthenticated attackers. The vulnerability was disclosed on December 17, 2019, affecting multiple Citrix products including NetScaler ADC, NetScaler Gateway, and Citrix SD-WAN WANOP appliance models (CERT VU).

Technical details

The vulnerability stems from the web server's failure to properly restrict access to Perl scripts available via the /vpns/ path. Attackers can exploit this by sending specially crafted requests containing directory traversal attempts (/../) to access the /vpns/ directory. The attack technique involves writing an XML file using directory traversal and subsequent command execution through the Perl Template Toolkit. The vulnerability received a CVSS v3.1 base score of 9.8 CRITICAL with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems, potentially leading to complete system compromise. Over 25,000 Citrix NetScaler endpoints were identified as vulnerable during the initial discovery period (CERT VU).

Exploitability

The vulnerability is highly exploitable as it requires no authentication and can be triggered through specially crafted HTTP requests. Multiple proof-of-concept exploits were publicly released, and the vulnerability has been actively exploited in the wild. A simple test can be performed by accessing the path '/vpn/../vpns/cfg/smb.conf' on affected systems (CERT VU).

Mitigation and workarounds

Citrix released permanent fixes for all supported versions and provided mitigation steps for systems that couldn't be immediately patched. The mitigation involves implementing responder policies to block requests containing directory traversal attempts and access to the /vpns/ directory. For standalone systems, specific commands were provided to implement these restrictions. Citrix strongly recommended applying the patches regardless of mitigation measures (Citrix Blog).

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management