LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-12991: Citrix SD-WAN and NetScaler Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-12991 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

CVE-2019-12991 is an authenticated command injection vulnerability affecting Citrix SD-WAN and NetScaler SD-WAN appliances. An attacker who already has valid credentials can abuse the flaw to run operating-system commands on the device. Because these appliances sit at the edge of many networks and often hold privileged connectivity, successful abuse can give an attacker a foothold for further movement or configuration changes. Public detail beyond the CISA summary is limited; teams should confirm exact scope and fixed builds against the vendor advisory.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In products of this class, user-supplied input that reaches a shell or system call is not adequately sanitized or constrained. When an authenticated session submits crafted data to a vulnerable management or configuration interface, the appliance may execute the attacker’s commands with the privileges of the underlying service. The CISA summary describes the issue simply as authenticated command injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance; no further exploit mechanics are provided here. Defenders should treat any authenticated administrative path on these devices as potentially able to reach the vulnerable code path until the vendor patch is applied and verified.

Am I affected? How to find it in your systems

Citrix SD-WAN and NetScaler SD-WAN appliances are typically deployed as physical or virtual edge devices for WAN optimization, secure connectivity, and traffic steering. They appear in data-center, branch, and cloud edge inventories, often managed through a web console or central orchestrator.

If version or configuration details cannot be confirmed internally, treat the appliance as potentially affected until the vendor advisory is checked.

How to remediate

Patching is the primary remediation. Apply the updates supplied by Citrix for the SD-WAN and NetScaler SD-WAN products exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; follow that guidance and verify the new version string after installation.

If you can't patch immediately

When immediate patching is not feasible, reduce exposure with compensating controls while the update is prepared.

These measures do not eliminate the vulnerability; they only lower the likelihood of successful exploitation until the vendor update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities on network appliances can lead to unauthorized access, configuration tampering, or lateral movement that ultimately exposes data. Known ransomware use of this CVE is not documented in the supplied facts, yet any confirmed compromise should still trigger incident-response procedures, credential resets, and a review of downstream systems the appliance could reach. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · SD-WAN and NetScaler
WeaknessCWE-78
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities