CVE-2024-29205: Ivanti Connect Secure
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.
Affected products
- Ivanti Connect Secure: from 9.1R18, before 9.1R18.5 (fixed in 9.1R18.5); from 22.6R2, before 22.6R2.3 (fixed in 22.6R2.3); from 9.1R17, before 9.1R17.4 (fixed in 9.1R17.4); from 22.2R, before 22.2R3 (fixed in 22.2R3); from 22.5R2, before 22.5R2.4 (fixed in 22.5R2.4); from 9.1R14, before 9.1R14.6 (fixed in 9.1R14.6); …
- Ivanti Policy Secure: from 22.5, before 22.5R1.3 (fixed in 22.5R1.3); from 9.1R18, before 9.1R18.5 (fixed in 9.1R18.5); from 9.1R17, before 9.1R17.4 (fixed in 9.1R17.4); from 22.2, before 22.2R3 (fixed in 22.2R3); version 22.5R1.3 only; version 9.1R18.5 only; …
Published 2024-04-25. Last modified 2026-06-17.