PT-2024-22806 · Ivanti · Ivanti Policy Secure+1

Published

2024-04-24

·

Updated

2024-07-03

·

CVE-2024-29205

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Connect Secure versions 9.x through 22.x Ivanti Policy Secure versions 9.x through 22.x
Description The issue is related to an Improper Check for Unusual or Exceptional Conditions in the web component, allowing a remote unauthenticated attacker to send specially crafted requests to cause service disruptions.
Recommendations For Ivanti Connect Secure versions 9.x through 22.x, update to a version that includes a fix for this issue. For Ivanti Policy Secure versions 9.x through 22.x, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the web component to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-29205

Affected Products

Ivanti Connect Secure
Ivanti Policy Secure