Skip to content

CVE-2019-19781: Shitrix

Path Traversal: Is CVE-2019-19781 real, exploitable, or a false positive? Here's the community verdict.

signals

public sources

Exploited in wild
Yes
CISA KEV
Public exploit
Metasploit +2
Metasploit/EDB/PoC
Base severity
9.8 Critical
CVSS
Exploitation prob.
100%
FIRST EPSS
Weakness
CWE-22 · Path Traversal
CWE

Confirmed exploited in the wild. Patch this first, regardless of the base score.

public exploits

links to sources — we don’t host code

A working exploit is publicly available from a maintained source. Treat this as higher urgency and verify your exposure.

baseline read

auto · not a community verdict

Real — exploited in the wild

CISA confirms active exploitation. Treat scanner hits as true positives unless your specific version or config is unaffected.

Based on CISA KEV

Confirm or dispute →
Affected:Citrix

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Published

Embed this verdict
TruePositive verdict for CVE-2019-19781
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2019-19781/badge.svg)](https://www.truepositive.app/cve/CVE-2019-19781)
HTML
<a href="https://www.truepositive.app/cve/CVE-2019-19781"><img src="https://www.truepositive.app/cve/CVE-2019-19781/badge.svg" alt="TruePositive verdict for CVE-2019-19781"></a>

Live badge that updates automatically as the community verdict changes.

Community ground truth

Be the first practitioner to weigh in

So far this is only TruePositive's editorial baseline from public sources. Add your real-world verdict below — it becomes the signal the next person triaging this relies on.

🥇 The first 50 practitioners to contribute earn a Founding Contributor badge.

In your experience, is this finding real and exploitable?

awaiting field verdicts
Real, but not a risk here
Not a real issue

Curated baseline: TruePositive's read from public sources is Real & exploitable — a starting point, not a community verdict.

No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.

Field notes & remediation

Verdicts are the quick signal. Notes are the evidence and fixes behind them.

  • 0
    Field note · TruePositive EditorialCurated

    A directory traversal flaw in Citrix ADC and Gateway (formerly NetScaler) leads to unauthenticated remote code execution. It was mass-exploited over the 2019 and 2020 holiday period, and it was worse because the patch arrived weeks after the first mitigation, so many appliances stayed exposed.

    Who is affected: Citrix ADC and Gateway on vulnerable firmware.

    Very important: the early mitigation (a responder policy) turned out to be bypassable on some builds, so an appliance that was only mitigated, not patched, may still have been hit.

    Commonly flagged by: Nessus, Qualys, Rapid7.

  • 0
    Remediation · TruePositive EditorialCurated

    Patch the firmware to a fixed version. Do not rely on the early responder-policy mitigation alone, because it was bypassable. Hunt for web shells, commonly dropped under the /netscaler/portal/templates path, and investigate if the appliance was exposed during the mass-exploitation window.

Add a field note or remediationoptional
Note type

What are you adding?

Markdown supported · minimum 20 characters.

Same weakness: CWE-22 · Path Traversal.