SUBJECT: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
TECH STACK: Citrix Application Delivery Controller (ADC), Citrix Gateway
DATE(S) ISSUED: 12/27/2019
NVD Last Modified: 01/20/2023
CRITICALITY: CRITICAL
OVERVIEW:
CVE-2019-19781 is a critical vulnerability that affects Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0. It allows skilled attackers to execute arbitrary code (RCE) on vulnerable systems through directory traversal attacks.
This could potentially allow an attacker to gain unauthorized access, exfiltrate confidential information, manipulate or disable critical system functions, and install malicious software and network compromises.
SOLUTION:
Several mitigation measures can be taken:
Apply Patches: The most effective mitigation is to apply patches provided by Citrix as soon as possible. Refer to the Citrix Security Advisory (https://support.citrix.com/article/CTX267027) for specific patch versions and download links.
Restrict Network Access: Limit access to the Citrix ADC and Gateway appliances from untrusted networks and users. Implement access control lists (ACLs) and firewalls to restrict incoming and outgoing traffic.
Disable Unused Features: Disable any unused features and virtual servers on the Citrix appliances to minimize the attack surface.
Monitor Logs and Activity: Regularly monitor logs and system activity for suspicious behavior that may indicate exploitation attempts. Implement intrusion detection and prevention systems (IDS/IPS) to further enhance security.
Prepare an Incident Response Plan: Have a well-defined incident response plan in place to quickly contain and remediate any potential security incidents.
Update Software Regularly: Keep Citrix ADC and Gateway software, as well as all other system software, up-to-date with the latest security patches.
REFERENCES:
Third Party Advisories:
- Packet Storm Security – Citrix Application Delivery Controller Gateway Remote Code Execution (VDB Entry)
- Packet Storm Security – Citrix Application Delivery Controller Gateway Remote Code Execution Traversal (VDB Entry)
- Packet Storm Security – Citrix Application Delivery Controller Gateway 10.5 Remote Code Execution (VDB Entry)
- Packet Storm Security – Citrix ADC NetScaler Directory Traversal Remote Code Execution (VDB Entry)
- Packet Storm Security – Citrix ADC Gateway Path Traversal (VDB Entry)
- Bad Packets – Citrix NetScaler Endpoints Vulnerable to CVE-2019-19781 (VDB Entry)
Confirmation & Additional Information:
- Citrix – CTX267027 – Citrix Application Delivery Controller and NetScaler Gateway Remote Code Execution Vulnerability
- Twitter – Bad Packets – Status Update on Citrix NetScaler Endpoints Vulnerable to CVE-2019-19781
Cross-References:



