First published: Wed Apr 24 2024(Updated: )
An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure (ICS) VPN | >=9.x<=9.x>=22.x<=22.x | |
Ivanti Policy Secure | >=9.x<=9.x>=22.x<=22.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29205 is classified as a high severity vulnerability due to its potential for remote exploitation leading to service disruptions.
To mitigate CVE-2024-29205, update Ivanti Connect Secure and Ivanti Policy Secure to the latest available versions that address this vulnerability.
CVE-2024-29205 affects Ivanti Connect Secure and Ivanti Policy Secure versions 9.x and 22.x.
CVE-2024-29205 allows a remote unauthenticated attacker to send specially crafted requests causing service disruptions.
No, CVE-2024-29205 can be exploited by a remote unauthenticated attacker.