CVE-2024-2049

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
12/03/2024
Last modified:
25/07/2025

Description

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_1000:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_110_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_110:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_1100:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_2000:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_210_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_210:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_2100:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_400_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)
cpe:2.3:h:citrix:sd-wan_400:-:*:*:*:standard:*:*:*
cpe:2.3:o:citrix:sd-wan_4000_firmware:*:*:*:*:standard:*:*:* 11.4.0 (including) 11.4.4.46 (excluding)