6.5
CVE-2024-2049
- EPSS 0.17%
- Veröffentlicht 12.03.2024 13:15:49
- Zuletzt bearbeitet 25.07.2025 15:36:48
- Quelle secure@citrix.com
- Teams Watchlist Login
- Unerledigt Login
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Sd-wan 1000 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 110 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 1100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 2000 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 210 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 2100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 400 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 4000 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 410 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 4100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 5100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 6100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 1000 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 1100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 2000 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 2100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 6100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
Citrix ≫ Sd-wan 5100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.383 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
secure@citrix.com | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.