7.5

CVE-2024-29205

An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Vendorivanti
Product connect_secure
Default Statusunaffected
Version 9.1R18.5
Status affected
Version 22.6R2.3
Status affected
Version 9.1R17.4
Status affected
Version 22.2R3
Status affected
Version 22.5R2.4
Status affected
Version 9.1R14.6
Status affected
Version 9.1R15.4
Status affected
Version 22.2R4.2
Status affected
Version 22.4R1.2
Status affected
Version 22.6R1.2
Status affected
Version 22.1R6.2
Status affected
Version 22.3R1.2
Status affected
Version 22.4R2.4
Status affected
Version 22.5R1.3
Status affected
Vendorivanti
Product policy_secure
Default Statusunaffected
Version 22.5R1.3
Status affected
Version 9.1R18.5
Status affected
Version 9.1R17.4
Status affected
Version 22.2R3
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.57% 0.808
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
support@hackerone.com 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.