CVE-2024-47909

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 121

Summary

CVE-2024-47909 is a stack-based buffer overflow vulnerability affecting Ivanti Connect Secure versions before 22.7R2.3 and Ivanti Policy Secure versions before 22.7R1.2. This issue allows a remote, authenticated attacker with administrative privileges to induce a denial of service by exploiting the buffer overflow. Successful exploitation could lead to unintended application behavior or crashes, resulting in a service outage. Ivanti urges users to upgrade to the latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Connect Secure
  • Ivanti Policy Secure