CVE-2024-22052: Null Pointer Dereference
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22052?
CVE-2024-22052 is rated as a high-severity vulnerability that can lead to a denial of service (DoS) attack.
How do I fix CVE-2024-22052?
To fix CVE-2024-22052, apply the latest security patch provided by Ivanti for affected versions of Ivanti Connect Secure and Ivanti Policy Secure.
What versions are affected by CVE-2024-22052?
CVE-2024-22052 affects Ivanti Connect Secure versions 9.x and 22.x, as well as Ivanti Policy Secure versions 9.x and 22.x.
How does CVE-2024-22052 exploit occur?
CVE-2024-22052 exploits a null pointer dereference in the IPSec component, allowing unauthenticated users to crash the service.
What impact does CVE-2024-22052 have on systems?
CVE-2024-22052 can cause systems to become temporarily unavailable, leading to potential disruptions in service.