CVE-2024-9844: High severity ivanti pulse connect secure vulnerability
Published Dec 10, 2024
·Updated
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
Affected Software
12 affected components
Ivanti Connect Secure<22.7
Ivanti Connect Secure=22.7
Ivanti Connect Secure=22.7-r1
Ivanti Connect Secure=22.7-r1.1
Ivanti Connect Secure=22.7-r1.2
Ivanti Connect Secure=22.7-r1.3
Ivanti Connect Secure=22.7-r1.4
Ivanti Connect Secure=22.7-r1.5
Ivanti Connect Secure=22.7-r2
Ivanti Connect Secure=22.7-r2.1
Ivanti Connect Secure=22.7-r2.2
Ivanti Connect Secure=22.7-r2.3
Event History
Dec 10, 2024
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9844?
CVE-2024-9844 has a medium severity level due to insufficient server-side controls allowing an authenticated attacker to bypass restrictions.
2
How do I fix CVE-2024-9844?
To fix CVE-2024-9844, upgrade Ivanti Connect Secure to version 22.7R2.4 or later.
3
What versions of Ivanti Connect Secure are affected by CVE-2024-9844?
CVE-2024-9844 affects all versions of Ivanti Connect Secure prior to 22.7R2.4.
4
What type of attack does CVE-2024-9844 enable?
CVE-2024-9844 enables remote authenticated attackers to bypass restrictions due to insufficient server-side controls.
5
Is there a patch available for CVE-2024-9844?
Yes, a patch is available in the form of an upgrade to Ivanti Connect Secure version 22.7R2.4.