CVE-2024-38654: Medium severity ivanti secure access client vulnerability
Published Nov 13, 2024
·Updated
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.
Affected Software
7 affected components
Ivanti Secure Access Client<22.7R3
Ivanti Secure Access Client<22.7
Ivanti Secure Access Client=22.7
Ivanti Secure Access Client=22.7-r1
Ivanti Secure Access Client=22.7-r1.1
Ivanti Secure Access Client=22.7-r2
Ivanti Secure Access Client=22.7-r3
Event History
Nov 13, 2024
CVE Published
via MITRE·01:54 AM
Data Sourced
via MITRE·01:54 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38654?
CVE-2024-38654 has a moderate severity level as it allows a local authenticated attacker to cause a denial of service.
2
How do I fix CVE-2024-38654?
To fix CVE-2024-38654, update the Ivanti Secure Access Client to version 22.7R3 or later.
3
Who is affected by CVE-2024-38654?
CVE-2024-38654 affects users of Ivanti Secure Access Client versions prior to 22.7R3.
4
What type of attack does CVE-2024-38654 enable?
CVE-2024-38654 enables a local authenticated attacker to exploit improper bounds checking and cause a denial of service.
5
Is there a workaround for CVE-2024-38654?
There is no known workaround for CVE-2024-38654; the recommended action is to update the software.