CVE-2019-19781

CVE Published 2019-12-27
Related CWE(s) CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Related Vendor(s) citrix
Related Product(s) gateway_firmware, application_delivery_controller_firmware, netscaler_gateway_firmware
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2019-19781

Report

NetScalers are under attack. Or… they were…

This report by CyberCX’s Digital Forensics and Incident Response (DFIR) team looks into the exploitation of known vulnerabilities in Citrix ...

Associated CAPEC Patterns

References