6.5

CVE-2024-2049

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CitrixSd-wan 1000 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 1000 Version- SwEditionstandard
CitrixSd-wan 110 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 110 Version- SwEditionstandard
CitrixSd-wan 1100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 1100 Version- SwEditionstandard
CitrixSd-wan 2000 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 2000 Version- SwEditionstandard
CitrixSd-wan 210 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 210 Version- SwEditionstandard
CitrixSd-wan 2100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 2100 Version- SwEditionstandard
CitrixSd-wan 400 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 400 Version- SwEditionstandard
CitrixSd-wan 4000 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 4000 Version- SwEditionstandard
CitrixSd-wan 410 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 410 Version- SwEditionstandard
CitrixSd-wan 4100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 4100 Version- SwEditionstandard
CitrixSd-wan 5100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 5100 Version- SwEditionstandard
CitrixSd-wan 6100 Firmware SwEditionstandard Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 6100 Version- SwEditionstandard
CitrixSd-wan 1000 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 1000 Version- SwEditionpremium
CitrixSd-wan 1100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 1100 Version- SwEditionpremium
CitrixSd-wan 2000 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 2000 Version- SwEditionpremium
CitrixSd-wan 2100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 2100 Version- SwEditionpremium
CitrixSd-wan 6100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 6100 Version- SwEditionpremium
CitrixSd-wan 5100 Firmware SwEditionpremium Version >= 11.4.0 < 11.4.4.46
   CitrixSd-wan 5100 Version- SwEditionpremium
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.383
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
secure@citrix.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.