PT-2024-22806 · Ivanti · Ivanti Policy Secure+1
Published
2024-04-24
·
Updated
2024-07-03
·
CVE-2024-29205
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Connect Secure versions 9.x through 22.x
Ivanti Policy Secure versions 9.x through 22.x
Description
The issue is related to an Improper Check for Unusual or Exceptional Conditions in the web component, allowing a remote unauthenticated attacker to send specially crafted requests to cause service disruptions.
Recommendations
For Ivanti Connect Secure versions 9.x through 22.x, update to a version that includes a fix for this issue.
For Ivanti Policy Secure versions 9.x through 22.x, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the web component to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Connect Secure
Ivanti Policy Secure