CVE-2024-2049 MEDIUM

CVE-2024-2049: Server-Side Request Forgery (SSRF)

Vendor Citrix
Product Citrix SD-WAN Standard/Premium Editions
Weakness CWE-918 · SSRF
Published March 12, 2024
Last update April 15, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

Key dates

02Disclosure timeline

March 12, 2024 CVE published
April 15, 2025 Record updated