Medium severity6.5NVD Advisory· Published Mar 12, 2024· Updated Jun 17, 2026
CVE-2024-2049
CVE-2024-2049
Description
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
Affected products
20cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:standard:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_110_firmware:*:*:*:*:standard:*:*:*Range: >=11.4.0,<11.4.4.46
cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:standard:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:standard:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_210_firmware:*:*:*:*:standard:*:*:*Range: >=11.4.0,<11.4.4.46
cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:standard:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_400_firmware:*:*:*:*:standard:*:*:*Range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_4000_firmware:*:*:*:*:standard:*:*:*Range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_410_firmware:*:*:*:*:standard:*:*:*Range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_4100_firmware:*:*:*:*:standard:*:*:*Range: >=11.4.0,<11.4.4.46
cpe:2.3:o:citrix:sd-wan_5100_firmware:*:*:*:*:premium:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_5100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_5100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
cpe:2.3:o:citrix:sd-wan_6100_firmware:*:*:*:*:premium:*:*:*+ 1 more
- cpe:2.3:o:citrix:sd-wan_6100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
- cpe:2.3:o:citrix:sd-wan_6100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
>=11.4.0 and <11.4.4.46+ 1 more
- (no CPE)range: >=11.4.0 and <11.4.4.46
- (no CPE)range: 11.4
Patches
Vulnerability mechanics
References
2- support.citrix.com/external/articlenvdVendor Advisory
- support.citrix.com/article/CTX617071/citrix-sdwan-security-bulletin-for-cve20242049nvdBroken Link
News mentions
0No linked articles in our index yet.