Skip to content
COOEY

EXPOSURES › CVE-2019-12989

CVE-2019-12989

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-12989 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatcheddata-breach

Citrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild.

Citrix SD-WAN and NetScaler products contained a SQL injection flaw (CVE-2019-12989) that was listed on CISA's KEV catalog, indicating active exploitation. DIB organizations must ensure these products are patched and monitored, as SQL injection can lead to data exfiltration and system compromise. The failure highlights the risk of relying on unpatched or vulnerable network infrastructure.

Shame score — A known SQL injection vulnerability in widely deployed Citrix products was actively exploited in the wild, demonstrating a failure to patch known CVEs and a lack of timely security updates.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized