PT-2024-2922 · Ivanti · Ivanti Avalanche

Published

2024-03-18

·

Updated

2024-07-03

·

CVE-2024-24991

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.3
Description The issue is related to a Null Pointer Dereference vulnerability in the WLAvalancheService component, which can be exploited by an authenticated remote attacker to cause a denial of service. This vulnerability is associated with pointer dereference errors.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the WLAvalancheService component to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-03087
CVE-2024-24991
ZDI-24-381

Affected Products

Ivanti Avalanche