Critical severity9.8CISA KEVNVD Advisory· Published Jul 16, 2019· Updated Jun 17, 2026
CVE-2019-12989
CVE-2019-12989
Description
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:*range: >=10.0.0,<10.0.8
- (no CPE)range: <10.0.8
cpe:2.3:a:citrix:sd-wan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citrix:sd-wan:*:*:*:*:*:*:*:*range: >=10.2.0,<10.2.3
- (no CPE)range: <10.2.3
- Citrix/SD-WANdescription
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.tenable.com/security/research/tra-2019-32nvdExploitThird Party Advisory
- www.securityfocus.com/bid/109133nvdBroken LinkThird Party AdvisoryVDB Entry
- support.citrix.com/article/CTX251987nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.