S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 29, 2024

CVE-2019-12990 Scanner

CVE-2019-12990 scanner - Local File Inclusion (LFI) vulnerability in Citrix SD-WAN Center

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-12990
9.8
CVSS

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Citrix SD-WAN Center is a central management console used to manage software-defined wide area networks. It is designed to simplify the management and optimization of the network by providing real-time analytics and control. This software is commonly used by businesses to improve network efficiency, increase security, and manage their WAN infrastructure effectively.

Recently, a vulnerability in Citrix SD-WAN Center was detected. The CVE-2019-12990 vulnerability was identified in versions 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8. This vulnerability allows Directory Traversal, which means that an attacker can access files and directories outside of the application's scope. This flaw enables attackers to gain unauthorized access to sensitive files and data within the system.

Exploiting the CVE-2019-12990 vulnerability in Citrix SD-WAN Center can lead to devastating consequences for businesses. Attackers can use this vulnerability to steal highly confidential data, such as financial information, customer data, and intellectual property. Moreover, a breach in the security system can put businesses at risk of losing their reputation, legal liabilities, and ultimately result in financial losses. The vulnerability leaves the business's network exposed to cyber attacks, which can significantly impact the business's productivity and reputation.

At s4e.io, we provide protection and assurance to businesses by detecting vulnerabilities in their digital assets. Our platform offers comprehensive and proactive security measures, which are a vital requirement for any business to ensure that their systems are safe from all known vulnerabilities. With our pro features, your business can get automatic security alerts and proactive threat analytics, reducing the risk of cyber attacks and data breaches. In conclusion, it is highly recommended that businesses take steps to protect themselves against the Citrix SD-WAN Center CVE-2019-12990 vulnerability.

 

REFERENCES

Solution Advice

Fortunately, there are a few precautions that can be taken to protect against the exploitation of this vulnerability. Here is a bullet point list of best practices to follow:

  • Update the software to the latest version (10.2.3 or 10.0.8)
  • Restrict access to the Citrix SD-WAN Center web-based management console
  • Disable guest login accounts
  • Utilize strong passwords for all user accounts
  • Implement intrusion detection systems

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-12990 scanner - Local File Inclusion (LFI) vulnerability in Citrix SD-WAN Center | S4E