PT-2024-39055 · Ivanti · Ivanti Policy Secure+1

Published

2024-11-11

·

Updated

2025-01-17

·

CVE-2024-8495

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Ivanti Connect Secure versions prior to 22.7R2.1 Ivanti Policy Secure versions prior to 22.7R1.1
Description: A null pointer dereference allows a remote unauthenticated attacker to cause a denial of service. This issue can be exploited by a remote attacker without authentication.
Recommendations: For Ivanti Connect Secure versions prior to 22.7R2.1, update to version 22.7R2.1 or later. For Ivanti Policy Secure versions prior to 22.7R1.1, update to version 22.7R1.1 or later.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-02303
CVE-2024-8495

Affected Products

Ivanti Connect Secure
Ivanti Policy Secure