Client-Side Enforcement of Server-Side Security in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-9844

 

Client-Side Enforcement of Server-Side Security in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-9844

Published: December 11, 2024


Vulnerability identifier: #VU101674
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9844
CWE-ID: CWE-602
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to improperly imposed controls in Secure Application Manager. A remote authenticated user can bypass implemented security restrictions and gain access to sensitive information or modify certain data.


Affected software

Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2024-9844

Install updates from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.4

External References

Related Security Bulletins