CVE-2024-8495: Null Pointer Dereference
Published Nov 12, 2024
·Updated
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
Affected Software
12 affected components
Ivanti Connect Secure<22.7
Ivanti Connect Secure=22.7
Ivanti Connect Secure=22.7-r1
Ivanti Connect Secure=22.7-r1.1
Ivanti Connect Secure=22.7-r1.2
Ivanti Connect Secure=22.7-r1.3
Ivanti Connect Secure=22.7-r1.4
Ivanti Connect Secure=22.7-r1.5
Ivanti Connect Secure=22.7-r2
Ivanti Policy Secure<22.7
Ivanti Policy Secure=22.7
Ivanti Policy Secure=22.7-r1
Event History
Nov 12, 2024
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8495?
CVE-2024-8495 has a high severity as it allows remote unauthenticated attackers to cause a denial of service.
2
How do I fix CVE-2024-8495?
To fix CVE-2024-8495, upgrade Ivanti Connect Secure to version 22.7R2.1 or Ivanti Policy Secure to version 22.7R1.1 or later.
3
What software is affected by CVE-2024-8495?
CVE-2024-8495 affects Ivanti Connect Secure versions prior to 22.7R2.1 and Ivanti Policy Secure versions prior to 22.7R1.1.
4
Can CVE-2024-8495 be exploited remotely?
Yes, CVE-2024-8495 can be exploited remotely without authentication.
5
What type of vulnerability is CVE-2024-8495?
CVE-2024-8495 is a null pointer dereference vulnerability.