November 3, 2021 · Applied Cybernetics Group
CVE-2019-19781 — Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
known ransomware use
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Citrix
- Product
- Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
- EPSS
- 100.0th percentile (score 1.000, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- ATT&CK
- T1059 , T1083 , T1133 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-19781
CISA short description
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
Required action
Apply updates per vendor instructions.
NVD description
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.