CVE-2024-2049Server-Side Request Forgery in Citrix Sd-wan Standard Premium Editions

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 58.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateJul 13

Description

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages16 packages

NVDcitrix/sd-wan_110_firmware11.4.011.4.4.46
NVDcitrix/sd-wan_210_firmware11.4.011.4.4.46
NVDcitrix/sd-wan_400_firmware11.4.011.4.4.46

🔴Vulnerability Details

1
GHSA
GHSA-cq2x-934m-8p64: Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 112024-03-12

📋Vendor Advisories

2
Citrix
Citrix SDWAN Security Bulletin for CVE-2024-20492024-07-13
Citrix
CVE-2024-2049: Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose l2024-03-12