CVE-2019-19781 is a critical directory traversal vulnerability affecting Citrix Application Delivery Controller (ADC) and Citrix Gateway versions 10.5 through 13.0. Rated with a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems via network access without requiring user interaction. The vulnerability is actively exploited in the wild, currently listed in CISA's Known Exploited Vulnerabilities catalog with links to ransomware campaigns, and functional exploit code is widely available in public frameworks like Metasploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:10.5:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:11.1:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:12.0:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:12.1:*:*:*:*:*:*:* | ||
13.0CPE matchmatch criteria | cpe:2.3:o:citrix:application_delivery_controller_firmware:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.