First published: Wed Dec 11 2024(Updated: )
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure (ICS) VPN | <22.7R2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37377 has a high severity rating due to its potential to cause denial of service.
To fix CVE-2024-37377, upgrade Ivanti Connect Secure to version 22.7R2.3 or later.
CVE-2024-37377 can allow an unauthenticated remote attacker to exploit a buffer overflow and potentially disrupt service.
CVE-2024-37377 is exploitable in Ivanti Connect Secure versions prior to 22.7R2.3.
Organizations using Ivanti Connect Secure versions before 22.7R2.3 are affected by CVE-2024-37377.