CVE-2024-9843

CVSS 3.1 Score 5 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 126

Summary

CVE-2024-9843 is a newly identified buffer over-read vulnerability affecting Ivanti Secure Access Client versions prior to 22.7R4. This issue enables a local, unauthenticated attacker to induce a denial of service. By sending specially crafted input data to the application, an adversary can cause the buffer to overflow, resulting in unintended program behavior or a crash. Consequently, the targeted system becomes unavailable, potentially disrupting critical operations. Organizations running the impacted Ivanti Secure Access Client are advised to apply the necessary patch as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share