CVE-2019-19781: Citrix ADC Path Traversal RCE
A path traversal vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway that lets an unauthenticated remote attacker write an arbitrary file to the appliance, then invoke it, achieving full remote code execution. It was exploited widely within weeks of disclosure and before an initial patch was available for all affected versions.
View the authoritative record on NVD ↗Affected software
- Citrix ADC and Citrix Gateway before 11.1.63.15, 12.0.63.13, 12.1.55.18, 13.0.47.24
- Citrix SD-WAN WANOP before 11.1.51a and 10.2.6b
How it's exploited
Send a crafted HTTP request containing directory traversal sequences to an unauthenticated Citrix ADC/Gateway management endpoint to write a malicious Perl script to a web-accessible directory, then request that script directly to achieve unauthenticated remote code execution.
Severity
CVE-2019-19781 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2019-19781 is categorized under CWE-22, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Path Traversal using OWASP ZAP and Nuclei and FFUF, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 9 dedicated rules for this weakness.
Tools: OWASP ZAP, Nuclei, FFUF
Remediation
Apply the Citrix-published fixed firmware build for the specific ADC or Gateway version in use, and check for indicators of compromise, since this flaw was mass exploited before patches were universally available.
Frequently asked questions
What is CVE-2019-19781?
A path traversal vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway that lets an unauthenticated remote attacker write an arbitrary file to the appliance, then invoke it, achieving full remote code execution. It was exploited widely within weeks of disclosure and before an initial patch was available for all affected versions.
How severe is CVE-2019-19781?
CVE-2019-19781 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2019-19781?
CVE-2019-19781 affects Citrix ADC and Citrix Gateway before 11.1.63.15, 12.0.63.13, 12.1.55.18, 13.0.47.24; Citrix SD-WAN WANOP before 11.1.51a and 10.2.6b.
How do you fix CVE-2019-19781?
Apply the Citrix-published fixed firmware build for the specific ADC or Gateway version in use, and check for indicators of compromise, since this flaw was mass exploited before patches were universally available.
Where is the authoritative record for CVE-2019-19781?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2019-19781 at https://nvd.nist.gov/vuln/detail/CVE-2019-19781, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest