CVE-2019-12990 is a critical directory traversal vulnerability affecting Citrix SD-WAN versions 10.2.x before 10.2.3 and NetScaler SD-WAN versions 10.0.x before 10.0.8. With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker to remotely access and potentially manipulate arbitrary files on the affected system, leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog or Hot List, exploit templates for local file inclusion exist, indicating a clear path for exploitation. Despite its severity and high EPSS score, there is currently no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0, < 10.0.8CPE matchmatch criteria | cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:* | ||
>= 10.2, < 10.2.3CPE matchmatch criteria | cpe:2.3:a:citrix:sd-wan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Citrix SD-WAN Center Multiple Vulnerabilities
Jul 2, 2019Citrix SD-WAN Center Multiple Vulnerabilities
Jul 2, 2019Citrix SD-WAN Center Multiple Vulnerabilities
Jul 2, 2019Citrix SD-WAN Center Multiple Vulnerabilities
Jul 2, 2019Citrix SD-WAN Center Multiple Vulnerabilities
Jul 2, 2019Citrix SD-WAN Center Multiple Vulnerabilities
Jul 2, 2019