Client-Side Enforcement of Server-Side Security in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-9844
Published: December 11, 2024
Vulnerability identifier: #VU101674
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9844
CWE-ID: CWE-602
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to improperly imposed controls in Secure Application Manager. A remote authenticated user can bypass implemented security restrictions and gain access to sensitive information or modify certain data.
Affected software
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2024-9844
Install updates from vendor's website.
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.4