PT-2024-2325 · Citrix · Citrix Sd-Wan Standard/Premium Editions

CVE-2024-2049

·

Published

2024-03-12

·

Updated

2024-03-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Citrix SD-WAN Standard/Premium Editions versions 11.4.0 through 11.4.4.46
Description The issue is related to Server-Side Request Forgery (SSRF) and is caused by insufficient validation of requests on the server side. This allows an attacker to disclose limited information from the appliance via access to the management IP by sending a specially crafted HTTP request.
Recommendations For versions 11.4.0 through 11.4.4.46, update to a version after 11.4.4.46 to resolve the issue. As a temporary workaround, consider restricting access to the management IP to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02267
CVE-2024-2049

Affected Products

Citrix Sd-Wan Standard/Premium Editions