Lucene search

K
cveCitrixCVE-2024-2049
HistoryMar 12, 2024 - 1:15 p.m.

CVE-2024-2049

2024-03-1213:15:49
CWE-918
Citrix
web.nvd.nist.gov
38
cve
citrix
sd-wan
ssrf
information security
vulnerability
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0

Percentile

9.0%

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Citrix SD-WAN Standard/Premium Editions",
    "vendor": "Citrix",
    "versions": [
      {
        "lessThan": "11.4.4.46",
        "status": "affected",
        "version": "11.4",
        "versionType": "patch"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0

Percentile

9.0%