PT-2024-2564 · Ivanti · Ivanti Policy Secure+1
Published
2024-04-02
·
Updated
2024-10-03
·
CVE-2024-21894
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Connect Secure versions 9.x through 22.x
Ivanti Policy Secure versions 9.x through 22.x
Description
A heap overflow vulnerability in the IPSec component of Ivanti Connect Secure and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests to crash the service, causing a DoS attack. In certain conditions, this may lead to the execution of arbitrary code. Approximately 16,500 Ivanti Connect Secure and Poly Secure gateways are susceptible to this flaw, with the majority located in the US, Japan, the UK, and other countries.
Recommendations
For Ivanti Connect Secure versions 9.x through 22.x: Update to a version that includes the fix for this vulnerability.
For Ivanti Policy Secure versions 9.x through 22.x: Update to a version that includes the fix for this vulnerability.
As a temporary workaround, consider restricting access to the IPSec component until a patch is available.
Avoid using the vulnerable IPSec component in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
NULL Pointer Dereference
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Connect Secure
Ivanti Policy Secure