EXPOSURES › CVE-2019-12989
CVE-2019-12989
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild.
Citrix SD-WAN and NetScaler products contained a SQL injection flaw (CVE-2019-12989) that was listed on CISA's KEV catalog, indicating active exploitation. DIB organizations must ensure these products are patched and monitored, as SQL injection can lead to data exfiltration and system compromise. The failure highlights the risk of relying on unpatched or vulnerable network infrastructure.
Shame score — A known SQL injection vulnerability in widely deployed Citrix products was actively exploited in the wild, demonstrating a failure to patch known CVEs and a lack of timely security updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |