RULE(RULE ID:324304)

Rule General Information
Release Date: 2020-02-14
Rule Name: Citrix SD-WAN Center Command Injection Vulnerability (CVE-2019-10883)
Severity:
CVE ID:
Rule Protection Details
Description: Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: https://support.citrix.com/article/CTX247737
https://support.citrix.com/v1/search?searchQuery=%22%22&lang=en&sort=cr_date_desc&prod=&pver=&ct=Security+Bulletin
https://www.tenable.com/security/research
https://www.tenable.com/security/research/tra-2019-18
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://support.citrix.com/article/CTX247737