CRITICAL
CVE-2024-21887
CVSS
9.1
KEV
Description
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Summary dbcve.org
Command injection vulnerability in web components of Ivanti Connect Secure and Policy Secure appliances allows authenticated administrators to execute arbitrary commands through specially crafted HTTP requests, achieving full compromise of the appliance.
Mitigation
Apply vendor-provided patches for affected versions (9.x, 22.x), restrict admin interface access to trusted networks, and monitor for unauthorized administrative activity until patching is complete.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
100%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21887
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.