7.5

CVE-2024-29205

An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerivanti
Produkt connect_secure
Default Statusunaffected
Version 9.1R18.5
Status affected
Version 22.6R2.3
Status affected
Version 9.1R17.4
Status affected
Version 22.2R3
Status affected
Version 22.5R2.4
Status affected
Version 9.1R14.6
Status affected
Version 9.1R15.4
Status affected
Version 22.2R4.2
Status affected
Version 22.4R1.2
Status affected
Version 22.6R1.2
Status affected
Version 22.1R6.2
Status affected
Version 22.3R1.2
Status affected
Version 22.4R2.4
Status affected
Version 22.5R1.3
Status affected
Herstellerivanti
Produkt policy_secure
Default Statusunaffected
Version 22.5R1.3
Status affected
Version 9.1R18.5
Status affected
Version 9.1R17.4
Status affected
Version 22.2R3
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.808
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
support@hackerone.com 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.