CVE-2024-13842
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2024-13842 is a newly disclosed vulnerability affecting Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3. This issue stems from a hardcoded key that enables a local authenticated attacker, who possesses admin privileges, to access and read sensitive data. The presence of this hardcoded key represents a bypass to secure data access mechanisms, posing a significant risk to organizational security. It is essential for affected organizations to apply the necessary patches to mitigate this vulnerability and prevent unauthorized data access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Connect Secure
- Ivanti Policy Secure
Affected Vendors
- Ivanti Software