Description
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19650 | A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack |
History
Thu, 03 Oct 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-703 | |
| CPEs | cpe:2.3:a:ivanti:connect_secure:9.0:-:*:*:*:*:*:* cpe:2.3:a:ivanti:policy_secure:22.0:*:*:*:*:*:*:* |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-10-03T21:40:23.298Z
Reserved: 2024-01-05T01:04:06.641Z
Link: CVE-2024-22052
Updated: 2024-08-01T22:35:34.818Z
Status : Modified
Published: 2024-04-04T20:15:08.333
Modified: 2024-11-21T08:55:28.100
Link: CVE-2024-22052
No data.
OpenCVE Enrichment
No data.
EUVD