Security
Loading…

CVE-2024-21887

CRITICALCVSS 9.1Known Exploited
Description

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

Timeline
Published:January 12th, 2024 5:15 PM
Last modified:August 4th, 2026 5:16 AM
Added to KEV:January 10th, 2024
CVSS Scoring

CVSS v3: 9.1 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

ivanti

Products

connect_securepolicy_secure
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute