Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-10883

67
FAUCET Score

CVE-2019-10883 is a critical command injection vulnerability affecting Citrix SD-WAN Center versions 10.2.x prior to 10.2.1 and NetScaler SD-WAN Center versions 10.0.x prior to 10.0.7. With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker to execute arbitrary commands remotely with high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, its high EPSS score and FAUCET Risk Score indicate a significant potential for future exploitation. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.1.0, <= 10.1.2CPE matchmatch criteria
cpe:2.3:a:citrix:citrix_sd-wan_center:*:*:*:*:*:*:*:*
>= 10.2.0, < 10.2.1CPE matchmatch criteria
cpe:2.3:a:citrix:citrix_sd-wan_center:*:*:*:*:*:*:*:*
>= 9.1, <= 9.3.6CPE matchmatch criteria
cpe:2.3:a:citrix:netscaler_sd-wan_center:*:*:*:*:*:*:*:*
>= 10.0.0, < 10.0.7CPE matchmatch criteria
cpe:2.3:a:citrix:netscaler_sd-wan_center:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
65.49%
Probability of exploitation in next 30 days
EPSS Percentile
99.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.6549 is in the 97th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

aristavendor investigatingvia llm_extracted
citrixvendor investigatingvia nvd_reference
View patch
opencartvendor investigatingvia llm_extracted
payloadcmsvendor investigatingvia llm_extracted
qlikvendor investigatingvia llm_extracted
safarivendor investigatingvia llm_extracted

Vendor Advisories (5)

aristallm-arista-49a974a9a037c138CRITICAL

Citrix SD-WAN Center and NetScaler SD-WAN Center Unauthenticated Remote Command Injection

Apr 10, 2019
opencartllm-opencart-14f913ced8ddfac7CRITICAL

Citrix SD-WAN Center and NetScaler SD-WAN Center Unauthenticated Remote Command Injection

Apr 10, 2019
safarillm-safari-465e7ae2431ddaa0CRITICAL

Citrix SD-WAN Center and NetScaler SD-WAN Center Unauthenticated Remote Command Injection

Apr 10, 2019
payloadcmsllm-payloadcms-280e0cf5058f856eCRITICAL

Citrix SD-WAN Center and NetScaler SD-WAN Center Unauthenticated Remote Command Injection

Apr 10, 2019
qlikllm-qlik-d629a71d9a423cc4CRITICAL

Citrix SD-WAN Center and NetScaler SD-WAN Center Unauthenticated Remote Command Injection

Apr 10, 2019

References

support.citrix.com / article/CTX247737
Vendor Advisory
support.citrix.com / v1/search
Vendor Advisory
tenable.com / security/research
Third Party Advisory
tenable.com / security/research/tra-2019-18
ExploitThird Party Advisory