9.8
CVE-2024-21894
- EPSS 18.99%
- Veröffentlicht 04.04.2024 23:15:15
- Zuletzt bearbeitet 21.11.2024 08:55:12
- Erkennungen
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r10
Ivanti ≫ Connect Secure Version 9.1 Update r11
Ivanti ≫ Connect Secure Version 9.1 Update r11.5
Ivanti ≫ Connect Secure Version 9.1 Update r12
Ivanti ≫ Connect Secure Version 9.1 Update r13
Ivanti ≫ Connect Secure Version 9.1 Update r14 SwEdition lts
Ivanti ≫ Connect Secure Version 9.1 Update r15
Ivanti ≫ Connect Secure Version 9.1 Update r16
Ivanti ≫ Connect Secure Version 9.1 Update r17
Ivanti ≫ Connect Secure Version 9.1 Update r18
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 9.1 Update r9
Ivanti ≫ Connect Secure Version 22.1
Ivanti ≫ Connect Secure Version 22.2
Ivanti ≫ Connect Secure Version 22.3
Ivanti ≫ Connect Secure Version 22.4
Ivanti ≫ Connect Secure Version 22.5
Ivanti ≫ Connect Secure Version 22.6
Ivanti ≫ Policy Secure Version 9.0 Update -
Ivanti ≫ Policy Secure Version 9.0 Update r1
Ivanti ≫ Policy Secure Version 9.0 Update r2
Ivanti ≫ Policy Secure Version 9.0 Update r2.1
Ivanti ≫ Policy Secure Version 9.0 Update r3
Ivanti ≫ Policy Secure Version 9.0 Update r3.1
Ivanti ≫ Policy Secure Version 9.0 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update -
Ivanti ≫ Policy Secure Version 9.1 Update r1
Ivanti ≫ Policy Secure Version 9.1 Update r10
Ivanti ≫ Policy Secure Version 9.1 Update r11
Ivanti ≫ Policy Secure Version 9.1 Update r12
Ivanti ≫ Policy Secure Version 9.1 Update r13
Ivanti ≫ Policy Secure Version 9.1 Update r14
Ivanti ≫ Policy Secure Version 9.1 Update r15
Ivanti ≫ Policy Secure Version 9.1 Update r16
Ivanti ≫ Policy Secure Version 9.1 Update r17
Ivanti ≫ Policy Secure Version 9.1 Update r18
Ivanti ≫ Policy Secure Version 9.1 Update r2
Ivanti ≫ Policy Secure Version 9.1 Update r3
Ivanti ≫ Policy Secure Version 9.1 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update r5
Ivanti ≫ Policy Secure Version 9.1 Update r6
Ivanti ≫ Policy Secure Version 9.1 Update r7
Ivanti ≫ Policy Secure Version 9.1 Update r8
Ivanti ≫ Policy Secure Version 9.1 Update r9
Ivanti ≫ Policy Secure Version 22.1
Ivanti ≫ Policy Secure Version 22.2
Ivanti ≫ Policy Secure Version 22.3
Ivanti ≫ Policy Secure Version 22.4
Ivanti ≫ Policy Secure Version 22.5
Ivanti ≫ Policy Secure Version 22.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 18.99% | 0.969 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| HackerOne | 8.2 | 3.9 | 4.2 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
|
CWE-703 Improper Check or Handling of Exceptional Conditions
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US