CVE-2024-50318

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 476

Summary

CVE-2024-50318 is a newly identified vulnerability in Ivanti Avalanche prior to version 6.4.6. This issue permits an unauthenticated attacker to trigger a denial of service (DoS) condition by exploiting a null pointer dereference. The vulnerability does not involve any authentication, making it a significant concern for organizations using Ivanti Avalanche. The null pointer dereference leads to a memory corruption, causing the application to crash and become unresponsive, resulting in a DoS condition. It is recommended that Ivanti Avalanche users upgrade to version 6.4.6 or later to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Avalanche

Affected Vendors

  • Ivanti Software Inc.