CRITICAL

CVE-2024-21887

Ivanti Connect Secure 2024-01-12 CVSS v3.1
CVSS
9.1
KEV

Description

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

Summary dbcve.org

Command injection vulnerability in web components of Ivanti Connect Secure and Policy Secure appliances allows authenticated administrators to execute arbitrary commands through specially crafted HTTP requests, achieving full compromise of the appliance.

Mitigation

Apply vendor-provided patches for affected versions (9.x, 22.x), restrict admin interface access to trusted networks, and monitor for unauthorized administrative activity until patching is complete.

Proof of Concept

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE