---
id: CVE-2019-19781
title: >-
  An issue was discovered in Citrix Application Delivery Controller (ADC) and
  Gateway 10.5, 11.1, 12.0, 12.1, and 13.0
summary: >-
  An issue was discovered in Citrix Application Delivery Controller (ADC) and
  Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: citrix
product: application_delivery_controller_firmware
affected:
  - application_delivery_controller_firmware = 10.5
  - application_delivery_controller_firmware = 11.1
  - application_delivery_controller_firmware = 12.0
  - application_delivery_controller_firmware = 12.1
  - application_delivery_controller_firmware = 13.0
  - netscaler_gateway_firmware = 10.5
  - netscaler_gateway_firmware = 11.1
  - netscaler_gateway_firmware = 12.0
  - netscaler_gateway_firmware = 12.1
  - gateway_firmware = 13.0
published: '2019-12-27'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-19781'
references:
  - url: >-
      http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.html
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.html
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.html
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html
    label: cve@mitre.org
  - url: >-
      https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/
    label: cve@mitre.org
  - url: 'https://forms.gle/eDf3DXZAv96oosfj6'
    label: cve@mitre.org
  - url: 'https://support.citrix.com/article/CTX267027'
    label: cve@mitre.org
  - url: 'https://twitter.com/bad_packets/status/1215431625766424576'
    label: cve@mitre.org
  - url: 'https://www.kb.cert.org/vuls/id/619785'
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://forms.gle/eDf3DXZAv96oosfj6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.citrix.com/article/CTX267027'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://twitter.com/bad_packets/status/1215431625766424576'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/619785'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19781
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99999
epssPercentile: 0.99998
kev: true
kevDateAdded: '2021-11-03'
kevDueDate: '2022-05-03'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-12T05:52:07.400Z'
exploits:
  exploitdb: true
  github: 44
  githubRepos:
    - 'https://github.com/projectzeroindia/CVE-2019-19781'
    - 'https://github.com/trustedsec/cve-2019-19781'
    - 'https://github.com/cisagov/check-cve-2019-19781'
  metasploit:
    - auxiliary/scanner/http/citrix_dir_traversal
    - exploit/freebsd/http/citrix_dir_traversal_rce
  nuclei:
    - CVE-2019-19781
  checkedAt: '2026-09-08T15:36:49.154Z'
---

## Overview

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

## Affected

- `application_delivery_controller_firmware = 10.5`
- `application_delivery_controller_firmware = 11.1`
- `application_delivery_controller_firmware = 12.0`
- `application_delivery_controller_firmware = 12.1`
- `application_delivery_controller_firmware = 13.0`
- `netscaler_gateway_firmware = 10.5`
- `netscaler_gateway_firmware = 11.1`
- `netscaler_gateway_firmware = 12.0`
- `netscaler_gateway_firmware = 12.1`
- `gateway_firmware = 13.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
