CVE-2024-13842: Medium severity ivanti pulse connect secure vulnerability
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13842?
CVE-2024-13842 has been classified as a high severity vulnerability due to the presence of a hardcoded key allowing unauthorized access to sensitive data.
How do I fix CVE-2024-13842?
To mitigate CVE-2024-13842, upgrade Ivanti Connect Secure to version 22.7R2.3 or later and Ivanti Policy Secure to version 22.7R1.3 or later.
Who is affected by CVE-2024-13842?
CVE-2024-13842 affects users of Ivanti Connect Secure versions prior to 22.7R2.3 and Ivanti Policy Secure versions prior to 22.7R1.3 who have local admin access.
What type of attack does CVE-2024-13842 enable?
CVE-2024-13842 enables a local authenticated attacker with admin privileges to read sensitive data stored within the affected Ivanti products.
Is CVE-2024-13842 targeted at a specific user group?
CVE-2024-13842 primarily targets organizations using Ivanti Connect Secure and Ivanti Policy Secure with compromised admin access.