RULE(RULE ID:324291)

Rule General Information
Release Date: 2020-02-14
Rule Name: NS Citrix SD-WAN Center Unauthenticated Remote Command Injection Vulnerability (CVE-2019-12985)
Severity:
CVE ID:
Rule Protection Details
Description: Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: SecurityFocusBID:109133
https://support.citrix.com/article/CTX251987
https://www.tenable.com/security/research/tra-2019-31
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://support.citrix.com/article/CTX251987