CVE-2024-37399: Null Pointer Dereference
Published Aug 14, 2024
·Updated
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Affected Software
20 affected components
Ivanti Avalanche=6.3.1
Ivanti Avalanche=6.3.1.1507
Ivanti Avalanche=6.3.2
Ivanti Avalanche Windows=6.3.2
Ivanti Avalanche=6.3.2
Ivanti Avalanche=6.3.2.3490
Ivanti Avalanche=6.3.2.3490
Ivanti Avalanche=6.3.3
Ivanti Avalanche=6.3.3
Ivanti Avalanche=6.3.3.101
Ivanti Avalanche=6.3.3.101
Ivanti Avalanche=6.3.4
Ivanti Avalanche=6.3.4
Ivanti Avalanche=6.3.4.153
Ivanti Avalanche=6.4.0
Ivanti Avalanche=6.4.1
Ivanti Avalanche=6.4.1
Ivanti Avalanche=6.4.1.207
Ivanti Avalanche=6.4.1.236
Ivanti Avalanche=6.4.2
Event History
Aug 14, 2024
CVE Published
via MITRE·02:38 AM
Data Sourced
via MITRE·02:38 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37399?
CVE-2024-37399 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2024-37399?
To fix CVE-2024-37399, it is recommended to upgrade to a patched version of Ivanti Avalanche.
3
Which versions of Ivanti Avalanche are affected by CVE-2024-37399?
CVE-2024-37399 affects Ivanti Avalanche versions 6.3.1 and potentially earlier versions.
4
Can CVE-2024-37399 be exploited remotely?
Yes, CVE-2024-37399 can be exploited by a remote unauthenticated attacker.
5
What impact does CVE-2024-37399 have on the service?
CVE-2024-37399 can cause the WLAvalancheService to crash, resulting in a denial of service.