VYPR
Medium severity6.5NVD Advisory· Published Mar 12, 2024· Updated Jun 17, 2026

CVE-2024-2049

CVE-2024-2049

Description

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

Affected products

20
  • cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:standard:*:*:*+ 1 more
    • cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
    • cpe:2.3:o:citrix:sd-wan_1000_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_110_firmware:*:*:*:*:standard:*:*:*
    Range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:standard:*:*:*+ 1 more
    • cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
    • cpe:2.3:o:citrix:sd-wan_1100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:standard:*:*:*+ 1 more
    • cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
    • cpe:2.3:o:citrix:sd-wan_2000_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_210_firmware:*:*:*:*:standard:*:*:*
    Range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:standard:*:*:*+ 1 more
    • cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
    • cpe:2.3:o:citrix:sd-wan_2100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_400_firmware:*:*:*:*:standard:*:*:*
    Range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_4000_firmware:*:*:*:*:standard:*:*:*
    Range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_410_firmware:*:*:*:*:standard:*:*:*
    Range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_4100_firmware:*:*:*:*:standard:*:*:*
    Range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_5100_firmware:*:*:*:*:premium:*:*:*+ 1 more
    • cpe:2.3:o:citrix:sd-wan_5100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
    • cpe:2.3:o:citrix:sd-wan_5100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
  • cpe:2.3:o:citrix:sd-wan_6100_firmware:*:*:*:*:premium:*:*:*+ 1 more
    • cpe:2.3:o:citrix:sd-wan_6100_firmware:*:*:*:*:premium:*:*:*range: >=11.4.0,<11.4.4.46
    • cpe:2.3:o:citrix:sd-wan_6100_firmware:*:*:*:*:standard:*:*:*range: >=11.4.0,<11.4.4.46
  • >=11.4.0 and <11.4.4.46+ 1 more
    • (no CPE)range: >=11.4.0 and <11.4.4.46
    • (no CPE)range: 11.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.