Critical Exposure in Citrix ADC (NetScaler) –…
ID: 2df623c8-07aa-533d-b75c-016a87cb18ed
STIX ID: report--2df623c8-07aa-533d-b75c-016a87cb18ed
Feed Name: TrustedSec blog
On December 17, 2019 Citrix published an advisory for CVE-2019-19781, a critical unauthenticated remote code execution vulnerability in Citrix ADC/NetScaler and Gateway (affecting versions 10.5 through 13.0). TrustedSec confirmed a fully working exploit that leverages directory traversal to call vulnerable scripts; Citrix provided mitigation workarounds (blocking directory traversal and restricting access to /vpns/ scripts) rather than an immediate patch, and widespread scanning for vulnerable appliances was already observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
