CVE-2024-37398: High severity ivanti secure access client vulnerability
Published Nov 13, 2024
·Updated
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Affected Software
5 affected components
Ivanti Secure Access Client<22.7
Ivanti Secure Access Client=22.7
Ivanti Secure Access Client=22.7-r1
Ivanti Secure Access Client=22.7-r2
Ivanti Secure Access Client=22.7-r3
Event History
Nov 13, 2024
CVE Published
via MITRE·01:54 AM
Data Sourced
via MITRE·01:54 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-37398?
CVE-2024-37398 has been classified as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2024-37398?
To mitigate CVE-2024-37398, upgrade the Ivanti Secure Access Client to version 22.7R4 or later.
3
Who is affected by CVE-2024-37398?
CVE-2024-37398 affects the Ivanti Secure Access Client versions prior to 22.7R4.
4
What type of attack does CVE-2024-37398 allow?
CVE-2024-37398 allows a local authenticated attacker to escalate their privileges on the affected system.
5
When was CVE-2024-37398 disclosed?
CVE-2024-37398 was disclosed in 2024, and users are advised to apply the appropriate updates promptly.