CVE-2019-12991

HIGH(8.8)KEVLikely Exploited

Citrix SD-WAN and NetScaler Command Injection Vulnerability

Description

CVE-2019-12991 is an authenticated OS command injection vulnerability in Citrix SD-WAN and NetScaler SD-WAN appliances. An authenticated attacker can exploit this flaw to inject and execute arbitrary operating system commands on the underlying system with elevated privileges. While authentication is required, the vulnerability enables complete system compromise once initial access is obtained. It was added to the CISA Known Exploited Vulnerabilities catalog on March 25, 2022, and with an EPSS score of 97.3% (99.9th percentile), exploitation is near-certain.

KEV Information

Vendor
Citrix
Product
SD-WAN and NetScaler
Date Added
March 25, 2022
Due Date
April 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
citrixnetscaler sd-wan>= 10.0.0, < 10.0.8
citrixsd-wan>= 10.2.0, < 10.2.3

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

CVE-2019-12991 is classified under CWE-78, which describes vulnerabilities where applications pass user-controlled input to operating system commands without adequate sanitization. The Citrix SD-WAN management interface fails to properly neutralize special characters in user input, enabling authenticated attackers to inject arbitrary commands into system-level operations.

Learn more: CWE-78 — Improper Neutralization of Special Elements used in an OS Command

Impact Analysis

CVE-2019-12991 allows authenticated attackers to execute arbitrary OS commands on Citrix SD-WAN and NetScaler SD-WAN appliances. Since SD-WAN appliances serve as critical network infrastructure components managing wide-area network traffic, compromise can have cascading effects across the entire organization's network. An attacker can intercept, redirect, or modify network traffic flowing through the SD-WAN fabric, access sensitive network configuration data and routing information, disable or degrade WAN connectivity affecting business operations, and use the compromised appliance as a pivot point for lateral movement. The EPSS score of 97.3% confirms near-certain exploitation for exposed instances.

Exploit Maturity

CVE-2019-12991 has been confirmed as actively exploited in the wild by CISA. While authentication is required, the availability of public exploit information and the high-value nature of SD-WAN infrastructure make this vulnerability an attractive target. Credential stuffing, phishing, or exploitation of companion vulnerabilities (such as CVE-2019-12989 for SQL injection) can provide the initial authentication needed. With an EPSS score of 97.3%, exploitation is near-certain for exposed Citrix SD-WAN appliances.

Remediation

  1. Apply Citrix security patches: Install the latest firmware updates from Citrix that address CVE-2019-12991, following the vendor's security bulletin.
  2. Restrict management interface access: Limit access to the SD-WAN management interface to trusted administrator workstations only, using network segmentation and firewall rules.
  3. Enforce strong authentication: Implement multi-factor authentication for all management access and enforce strong password policies to reduce the risk of credential compromise.
  4. Audit administrative accounts: Review all administrator accounts, remove unused accounts, and ensure the principle of least privilege is applied.
  5. Monitor management interface activity: Enable comprehensive logging and monitoring for all management interface access, with alerts for unusual commands or access patterns.

Technical Details

CVE-2019-12991 is an OS command injection vulnerability in the web-based management interface of Citrix SD-WAN (formerly NetScaler SD-WAN) appliances. The vulnerability exists because the management interface does not properly sanitize user-supplied input in certain administrative functions before incorporating it into operating system commands. An authenticated attacker with access to the management interface can craft requests containing shell metacharacters that escape the intended command context and execute arbitrary commands on the underlying operating system. The commands execute with the privileges of the web application, which typically has elevated or root-level access to perform system administration tasks.

Frequently Asked Questions

Is CVE-2019-12991 being actively exploited?

Yes. CISA has confirmed active exploitation of CVE-2019-12991 and added it to the Known Exploited Vulnerabilities catalog. The EPSS score of 97.3% indicates near-certain exploitation for exposed appliances.

What products are affected by CVE-2019-12991?

CVE-2019-12991 affects Citrix SD-WAN and NetScaler SD-WAN appliances. These are enterprise network infrastructure devices used for managing and optimizing wide-area network connectivity.

How do I fix CVE-2019-12991?

Apply the latest firmware patches from Citrix that address CVE-2019-12991. Restrict management interface access to trusted networks, enforce multi-factor authentication, and audit all administrative accounts.

How severe is CVE-2019-12991?

CVE-2019-12991 is a high-severity command injection vulnerability. While authentication is required, it enables complete system compromise of critical network infrastructure. Attackers can chain this with other vulnerabilities to gain initial access.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score74.05%
EPSS Percentile99.4%

Dates

PublishedJuly 16, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.