NetScaler ADC and Gateway
CVE-2019-12989: SD-WAN and NetScaler SQL Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Published
ExploitedYes, in CISA KEVAdded 25 Mar 2022
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.8
EPSS95%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| n/a n/a | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Exploitation
CISA lists this CVE as exploited in the wild since 25 Mar 2022.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.