CVE-2019-10883OS Command Injection in Citrix Sd-wan Center

Severity
9.8CRITICALNVD
EPSS
41.8%
top 2.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 24

Description

Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDcitrix/netscaler_sd-wan_center10.0.010.0.7+1
NVDcitrix/citrix_sd-wan_center10.2.010.2.1+1
citrixcitrix/sd-wan

🔴Vulnerability Details

1
GHSA
GHSA-9xmm-v8h7-ccm7: Citrix SD-WAN Center 102022-05-24

📋Vendor Advisories

2
Citrix
CVE-2019-10883: Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.2019-06-03
Citrix
Citrix SD-WAN Center Security Updates

🕵️Threat Intelligence

1
Tenable
Critical OS Command Injection Vulnerability in Citrix SD-WAN Center Discovered2019-04-11