CVE-2024-2049

MEDIUMCVSS 6.50% EPSS

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

Published 2024-03-12 · last modified 2026-06-17

Affected products

VendorProduct
citrixcitrix sd-wan standard/premium editions
citrixsd-wan_1000_firmware
citrixsd-wan_1100_firmware
citrixsd-wan_110_firmware
citrixsd-wan_2000_firmware
citrixsd-wan_2100_firmware
citrixsd-wan_210_firmware
citrixsd-wan_4000_firmware
citrixsd-wan_400_firmware
citrixsd-wan_4100_firmware
citrixsd-wan_410_firmware
citrixsd-wan_5100_firmware
citrixsd-wan_6100_firmware

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.