An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Citrix Adc | — | In Citrix ADC Release 12.1 builds before 51.16/51.19 and 50.31, a bug exists that affects responder and rewrite policies bound to VPN virtual servers causing them not to process the packets that matched policy rules. Citrix recommends customers to update to an unaffected build for the mitigation steps to apply properly for CVE-2019-19781Apply the fixed builds that have been released for Citrix ADC versions 11.1 and Citrix Gateway versions 11.1.Apply the fixed builds that have been released for Citrix ADC versions 12.1 and Citrix Gateway versions 12.1.Apply the fixed builds that have been released for Citrix ADC versions 12.0 and Citrix Gateway versions 12.0.Apply the mitigation steps listed in the article by Citrix.Apply the fixed builds that have been released for Citrix ADC versions 13.0 and Citrix Gateway versions 13.0Apply the fixed builds that have been released for Citrix ADC versions 10.5 and Citrix Gateway versions 10.5. | Jan 10, 2020 | Dec 27, 2019 |
| Freebsd | — | Upgrade p5-Template-Toolkit | Jan 15, 2020 | Jan 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub