CVE-2024-13843: Medium severity ivanti pulse connect secure vulnerability
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13843?
CVE-2024-13843 is considered a high-severity vulnerability due to the potential exposure of sensitive data.
How do I fix CVE-2024-13843?
To fix CVE-2024-13843, upgrade Ivanti Connect Secure to version 22.7R2.6 or later and Ivanti Policy Secure to version 22.7R1.3 or later.
What does CVE-2024-13843 affect?
CVE-2024-13843 affects Ivanti Connect Secure versions before 22.7R2.6 and Ivanti Policy Secure versions before 22.7R1.3.
Who can exploit CVE-2024-13843?
CVE-2024-13843 can be exploited by local authenticated attackers with admin privileges.
What is the impact of CVE-2024-13843?
The impact of CVE-2024-13843 includes the potential for attackers to read sensitive data that is stored in cleartext.