CVE-2024-37401: High severity ivanti pulse connect secure vulnerability
Published Dec 11, 2024
·Updated
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
Affected Software
17 affected components
Ivanti Connect Secure<22.7R2.1
Ivanti Connect Secure<22.7
Ivanti Connect Secure=22.7
Ivanti Connect Secure=22.7-r1
Ivanti Connect Secure=22.7-r1.1
Ivanti Connect Secure=22.7-r1.2
Ivanti Connect Secure=22.7-r1.3
Ivanti Connect Secure=22.7-r1.4
Ivanti Connect Secure=22.7-r1.5
Ivanti Connect Secure=22.7-r2
Ivanti Connect Secure=22.7-r2.1
Ivanti Connect Secure=22.7-r2.2
Ivanti Connect Secure=22.7-r2.3
Ivanti Policy Secure<22.7
Ivanti Policy Secure=22.7
Ivanti Policy Secure=22.7-r1
Ivanti Policy Secure=22.7-r1.1
Event History
Dec 11, 2024
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionSeverity
Dec 12, 2024
Data Sourced
via NVD·01:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37401?
CVE-2024-37401 has a high severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2024-37401?
To fix CVE-2024-37401, upgrade Ivanti Connect Secure to version 22.7R2.1 or later.
3
What type of vulnerability is CVE-2024-37401?
CVE-2024-37401 is classified as an out-of-bounds read vulnerability.
4
Who is affected by CVE-2024-37401?
CVE-2024-37401 affects users of Ivanti Connect Secure versions prior to 22.7R2.1.
5
Can CVE-2024-37401 be exploited remotely?
Yes, CVE-2024-37401 can be exploited by remote unauthenticated attackers.