← back
CVE-2019-19781

CVE-2019-19781

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-22
In short

Citrix ADC and Gateway versions 10.5 through 13.0 contain a directory traversal vulnerability that allows attackers to access files and directories outside their intended location on the server, potentially exposing sensitive system information and configurations.

Technical detail

A path traversal vulnerability in Citrix ADC/Gateway enables unauthenticated remote attackers to bypass access controls and read arbitrary files on the affected system by manipulating file paths with directory traversal sequences (e.g., ../). The vulnerability affects multiple versions and can lead to unauthorized disclosure of sensitive data including credentials and system configuration.

Summary generated and translated by AI from the official description.
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
public PoCs found54
githubgithub.com/trustedsec/cve-2019-19781572githubgithub.com/projectzeroindia/CVE-2019-19781366githubgithub.com/mpgn/CVE-2019-19781158githubgithub.com/MalwareTech/CitrixHoneypot120githubgithub.com/cisagov/check-cve-2019-19781109githubgithub.com/mandiant/ioc-scanner-CVE-2019-1978194githubgithub.com/jas502n/CVE-2019-1978185githubgithub.com/citrix/ioc-scanner-CVE-2019-1978158githubgithub.com/aqhmal/CVE-2019-1978111githubgithub.com/w4fz5uck5/CVE-2019-19781-CitrixRCE10githubgithub.com/ianxtianxt/CVE-2019-197817githubgithub.com/VladRico/CVE-2019-197817githubgithub.com/unknowndevice64/Exploits_CVE-2019-197814githubgithub.com/k-fire/CVE-2019-19781-exploit3githubgithub.com/onSec-fr/CVE-2019-19781-Forensic3githubgithub.com/j81blog/ADC-197813githubgithub.com/oways/CVE-2019-197812githubgithub.com/DanielWep/CVE-NetScalerFileSystemCheck2githubgithub.com/andripwn/CVE-2019-197812githubgithub.com/Vulnmachines/Ctirix_RCE-CVE-2019-197811githubgithub.com/r4ulcl/CVE-2019-197811githubgithub.com/redscan/CVE-2019-197811githubgithub.com/nmanzi/webcvescanner1githubgithub.com/Azeemering/CVE-2019-19781-DFIR-Notes0githubgithub.com/tpdlshdmlrkfmcla/CVE-2019-197810githubgithub.com/zerobytesecure/CVE-2019-197810githubgithub.com/pwn3z/CVE-2019-19781-Citrix0githubgithub.com/becrevex/Citrix_CVE-2019-197810githubgithub.com/jamesjguthrie/Shitrix-CVE-2019-197810githubgithub.com/hollerith/CVE-2019-197810githubgithub.com/mekhalleh/citrix_dir_traversal_rce0githubgithub.com/zgelici/CVE-2019-19781-Checker0githubgithub.com/digitalshadows/CVE-2019-19781_IOCs0githubgithub.com/autocode07/cisagov__check-cve-2019-19781.4142e02b0githubgithub.com/0xams/citrixvulncheck0githubgithub.com/EliusHHimel/citrix-honeypot0githubgithub.com/darren646/CVE-2019-19781POC0githubgithub.com/Roshi99/Remote-Code-Execution-Exploit-for-Citrix-Application-Delivery-Controller-and-Citrix-Gateway-CVE-2010githubgithub.com/yukar1z0e/CVE-2019-197810githubgithub.com/SharpHack/CVE-2019-197810githubgithub.com/qiong-qi/CVE-2019-19781-poc0githubgithub.com/Castaldio86/Detect-CVE-2019-197810githubgithub.com/awesome-security/citrixmash_scanner0githubgithub.com/b510/CVE-2019-197810githubgithub.com/digitalgangst/massCitrix0githubgithub.com/L4r1k/CitrixNetscalerAnalysis0cve_referencepacketstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.htmlunverifiedcve_referencepacketstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.htmlunverifiedcve_referencepacketstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/47901unverifiedexploitdbwww.exploit-db.com/exploits/47913unverifiedexploitdbwww.exploit-db.com/exploits/47930unverifiedcve_referencepacketstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.htmlunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →