8.8
CVE-2024-9420
- EPSS 1.43%
- Veröffentlicht 12.11.2024 16:15:26
- Zuletzt bearbeitet 13.03.2025 16:15:25
- Erkennungen
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 9.1
Ivanti ≫ Connect Secure Version >= 21.9 < 22.7
Ivanti ≫ Connect Secure Version 9.1 Update -
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r1.0
Ivanti ≫ Connect Secure Version 9.1 Update r10
Ivanti ≫ Connect Secure Version 9.1 Update r10.0
Ivanti ≫ Connect Secure Version 9.1 Update r10.2
Ivanti ≫ Connect Secure Version 9.1 Update r11
Ivanti ≫ Connect Secure Version 9.1 Update r11.0
Ivanti ≫ Connect Secure Version 9.1 Update r11.1
Ivanti ≫ Connect Secure Version 9.1 Update r11.3
Ivanti ≫ Connect Secure Version 9.1 Update r11.4
Ivanti ≫ Connect Secure Version 9.1 Update r11.5
Ivanti ≫ Connect Secure Version 9.1 Update r12
Ivanti ≫ Connect Secure Version 9.1 Update r12.1
Ivanti ≫ Connect Secure Version 9.1 Update r12.2
Ivanti ≫ Connect Secure Version 9.1 Update r13
Ivanti ≫ Connect Secure Version 9.1 Update r13.1
Ivanti ≫ Connect Secure Version 9.1 Update r14
Ivanti ≫ Connect Secure Version 9.1 Update r14.4
Ivanti ≫ Connect Secure Version 9.1 Update r15
Ivanti ≫ Connect Secure Version 9.1 Update r15.2
Ivanti ≫ Connect Secure Version 9.1 Update r16
Ivanti ≫ Connect Secure Version 9.1 Update r16.1
Ivanti ≫ Connect Secure Version 9.1 Update r17
Ivanti ≫ Connect Secure Version 9.1 Update r17.1
Ivanti ≫ Connect Secure Version 9.1 Update r17.2
Ivanti ≫ Connect Secure Version 9.1 Update r18
Ivanti ≫ Connect Secure Version 9.1 Update r18.1
Ivanti ≫ Connect Secure Version 9.1 Update r18.2
Ivanti ≫ Connect Secure Version 9.1 Update r18.3
Ivanti ≫ Connect Secure Version 9.1 Update r18.7
Ivanti ≫ Connect Secure Version 9.1 Update r18.8
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r2.0
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r3.0
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.0
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r5.0
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r6.0
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Connect Secure Version 9.1 Update r7.0
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 9.1 Update r8.0
Ivanti ≫ Connect Secure Version 9.1 Update r8.1
Ivanti ≫ Connect Secure Version 9.1 Update r8.2
Ivanti ≫ Connect Secure Version 9.1 Update r8.4
Ivanti ≫ Connect Secure Version 9.1 Update r9
Ivanti ≫ Connect Secure Version 9.1 Update r9.0
Ivanti ≫ Connect Secure Version 9.1 Update r9.1
Ivanti ≫ Connect Secure Version 9.1 Update r9.2
Ivanti ≫ Connect Secure Version 22.7 Update -
Ivanti ≫ Connect Secure Version 22.7 Update r1
Ivanti ≫ Connect Secure Version 22.7 Update r1.1
Ivanti ≫ Connect Secure Version 22.7 Update r1.2
Ivanti ≫ Connect Secure Version 22.7 Update r1.3
Ivanti ≫ Connect Secure Version 22.7 Update r1.4
Ivanti ≫ Connect Secure Version 22.7 Update r1.5
Ivanti ≫ Connect Secure Version 22.7 Update r2
Ivanti ≫ Connect Secure Version 22.7 Update r2.1
Ivanti ≫ Connect Secure Version 22.7 Update r2.2
Ivanti ≫ Policy Secure Version < 22.7
Ivanti ≫ Policy Secure Version 22.7 Update -
Ivanti ≫ Policy Secure Version 22.7 Update r1
Ivanti ≫ Policy Secure Version 22.7 Update r1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.43% | 0.708 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs