Ivanti Connect Secure Suffers from Heap Overflow Vulnerability, Leading to DoS Attacks

CVE-2024-21894
9.8CRITICAL

Key Information

Vendor
Ivanti
Status
Connect Secure
Policy Secure
Vendor
CVE Published:
4 April 2024

Badges

đź‘ľ Exploit Existsđź“° News Worthy

Summary

Vulnerability CVE-2024-21894 affects Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure and allows an unauthenticated attacker to crash the service, leading to a denial-of-service (DoS) attack. In certain conditions, this vulnerability may also result in the execution of arbitrary code. It is part of a group of vulnerabilities that include heap overflow, null pointer dereference, and XML entity expansion, which pose serious threats to the security of the affected software. Ivanti has released patches to address these vulnerabilities and organizations are strongly recommended to apply these updates as soon as possible to mitigate the risk. No evidence of exploitation by threat actors, including ransomware groups, has been reported so far.

Affected Version(s)

Connect Secure < 22.1R6.2

Connect Secure < 22.2R4.2

Connect Secure < 22.3R1.2

News Articles

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź‘ľ

    Exploit exists.

  • Risk change from: 9.8 to: 8.2 - (HIGH)

  • Vulnerability published.

  • First article discovered by BleepingComputer

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)13 News Article(s)
.