CVE-2019-19781
CRITICAL WAF: High
CVSS 9.8
Published: 2019-12-27
CWE-22 CWE-22
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
WAF Coverage Analysis
Path Traversal
High WAF Coverage
OWASP: A01:2021 Broken Access Control
930xxx - Local File Inclusion
Path Traversal
High WAF Coverage
OWASP: A01:2021 Broken Access Control
930xxx - Local File Inclusion
Affected Software
| Vendor | Product | Version |
|---|---|---|
| citrix | application_delivery_controller_firmware | 10.5 |
| citrix | application_delivery_controller_firmware | 11.1 |
| citrix | application_delivery_controller_firmware | 12.0 |
| citrix | application_delivery_controller_firmware | 12.1 |
| citrix | application_delivery_controller_firmware | 13.0 |
| citrix | netscaler_gateway_firmware | 10.5 |
| citrix | netscaler_gateway_firmware | 11.1 |
| citrix | netscaler_gateway_firmware | 12.0 |
| citrix | netscaler_gateway_firmware | 12.1 |
| citrix | gateway_firmware | 13.0 |
References
- packetstormsecurity.com (Third Party Advisory, VDB Entry)
- packetstormsecurity.com (Third Party Advisory, VDB Entry)
- packetstormsecurity.com (Third Party Advisory, VDB Entry)
- packetstormsecurity.com (Third Party Advisory, VDB Entry)
- packetstormsecurity.com (Third Party Advisory, VDB Entry)
- badpackets.net (Broken Link, Third Party Advisory)
- forms.gle (Third Party Advisory)
- support.citrix.com (Vendor Advisory)
- twitter.com (Broken Link, Third Party Advisory)
- www.kb.cert.org (Third Party Advisory, US Government Resource)