CVE-2024-50318: Null Pointer Dereference
Published Nov 12, 2024
·Updated
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
Affected Software
1 affected component
Ivanti Avalanche<6.4.6
Event History
Nov 12, 2024
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-50318?
CVE-2024-50318 has a medium severity level due to its potential to cause denial of service.
2
How does CVE-2024-50318 affect Ivanti Avalanche?
CVE-2024-50318 affects Ivanti Avalanche versions prior to 6.4.6 by allowing remote unauthenticated attackers to trigger a null pointer dereference.
3
How do I fix CVE-2024-50318?
To fix CVE-2024-50318, upgrade Ivanti Avalanche to version 6.4.6 or later.
4
Can CVE-2024-50318 be exploited remotely?
Yes, CVE-2024-50318 can be exploited by a remote unauthenticated attacker.
5
What causes the vulnerability in CVE-2024-50318?
The vulnerability in CVE-2024-50318 is caused by a null pointer dereference in the software's handling of certain requests.