CVE-2024-2049
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
Affected (18)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 1000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 110 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 1100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 2000 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 210 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 2100 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 400 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 4000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 410 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 4100 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 5100 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 6100 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 1000 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 1100 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 2000 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 2100 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 6100 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.4.4.46 |
| Running on/with | Platform Versions |
|---|---|
Citrix Sd Wan 5100 | All versions |
References (3)
Source: secure@citrix.com
Broken Link
Source: nvd@nist.gov
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Timeline
No history available yet.