CVE Vulnerabilities

CVE-2024-37399

NULL Pointer Dereference

Published: Aug 14, 2024 | Modified: Aug 15, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Avalanche Ivanti 6.3.1 (including) 6.3.1 (including)
Avalanche Ivanti 6.3.1.1507 (including) 6.3.1.1507 (including)
Avalanche Ivanti 6.3.2 (including) 6.3.2 (including)
Avalanche Ivanti 6.3.2.3490 (including) 6.3.2.3490 (including)
Avalanche Ivanti 6.3.3 (including) 6.3.3 (including)
Avalanche Ivanti 6.3.3.101 (including) 6.3.3.101 (including)
Avalanche Ivanti 6.3.4 (including) 6.3.4 (including)
Avalanche Ivanti 6.3.4.153 (including) 6.3.4.153 (including)
Avalanche Ivanti 6.4.0 (including) 6.4.0 (including)
Avalanche Ivanti 6.4.1 (including) 6.4.1 (including)
Avalanche Ivanti 6.4.1.207 (including) 6.4.1.207 (including)
Avalanche Ivanti 6.4.1.236 (including) 6.4.1.236 (including)
Avalanche Ivanti 6.4.2 (including) 6.4.2 (including)

Potential Mitigations

References