CVE Vulnerabilities

CVE-2024-37399

NULL Pointer Dereference

Published: Aug 14, 2024 | Modified: Aug 15, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
AvalancheIvanti6.3.1 (including)6.3.1 (including)
AvalancheIvanti6.3.1.1507 (including)6.3.1.1507 (including)
AvalancheIvanti6.3.2 (including)6.3.2 (including)
AvalancheIvanti6.3.2.3490 (including)6.3.2.3490 (including)
AvalancheIvanti6.3.3 (including)6.3.3 (including)
AvalancheIvanti6.3.3.101 (including)6.3.3.101 (including)
AvalancheIvanti6.3.4 (including)6.3.4 (including)
AvalancheIvanti6.3.4.153 (including)6.3.4.153 (including)
AvalancheIvanti6.4.0 (including)6.4.0 (including)
AvalancheIvanti6.4.1 (including)6.4.1 (including)
AvalancheIvanti6.4.1.207 (including)6.4.1.207 (including)
AvalancheIvanti6.4.1.236 (including)6.4.1.236 (including)
AvalancheIvanti6.4.2 (including)6.4.2 (including)

Potential Mitigations

References