CVE-2024-12058: Medium severity ivanti pulse connect secure vulnerability
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12058?
CVE-2024-12058 is classified as a medium severity vulnerability.
How do I fix CVE-2024-12058?
To remediate CVE-2024-12058, upgrade Ivanti Connect Secure to version 22.7R2.6 or later and Ivanti Policy Secure to version 22.7R1.3 or later.
Who is affected by CVE-2024-12058?
CVE-2024-12058 affects users of Ivanti Connect Secure versions prior to 22.7R2.6 and Ivanti Policy Secure versions prior to 22.7R1.3.
What type of attack does CVE-2024-12058 enable?
CVE-2024-12058 allows a remote authenticated attacker with admin privileges to read arbitrary files on the affected systems.
Is there a workaround for CVE-2024-12058?
There are no known workarounds for CVE-2024-12058; the only solution is to upgrade to the patched versions.