CVE-2024-9845: High severity ivanti automation vulnerability
Published Dec 11, 2024
·Updated
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
Affected Software
1 affected component
Ivanti Automation<2024.4.0.1
Event History
Dec 11, 2024
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9845?
CVE-2024-9845 is classified as a high severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2024-9845?
To remediate CVE-2024-9845, upgrade Ivanti Automation to version 2024.4.0.1 or later.
3
Who is affected by CVE-2024-9845?
CVE-2024-9845 affects users of Ivanti Automation versions prior to 2024.4.0.1.
4
What type of attack is associated with CVE-2024-9845?
CVE-2024-9845 allows a local authenticated attacker to achieve local privilege escalation.
5
When was CVE-2024-9845 reported?
CVE-2024-9845 was reported in December 2024.