7.2

CVE-2023-41719

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IvantiConnect Secure Version21.9 Updater1
IvantiConnect Secure Version21.12 Updater1
IvantiConnect Secure Version22.1 Updater1
IvantiConnect Secure Version22.1 Updater6
IvantiConnect Secure Version22.2 Updater1
IvantiConnect Secure Version22.3 Updater1
IvantiConnect Secure Version22.4 Updater1
IvantiConnect Secure Version22.5 Updater1.1
IvantiConnect Secure Version22.5 Updater2.1
IvantiConnect Secure Version22.6 Update-
IvantiConnect Secure Version22.6 Updater1
IvantiConnect Secure Version9.1 Updater1
IvantiConnect Secure Version9.1 Updater10
IvantiConnect Secure Version9.1 Updater10.2
IvantiConnect Secure Version9.1 Updater11
IvantiConnect Secure Version9.1 Updater11.1
IvantiConnect Secure Version9.1 Updater11.3
IvantiConnect Secure Version9.1 Updater11.4
IvantiConnect Secure Version9.1 Updater11.5
IvantiConnect Secure Version9.1 Updater12
IvantiConnect Secure Version9.1 Updater12.1
IvantiConnect Secure Version9.1 Updater12.2
IvantiConnect Secure Version9.1 Updater13
IvantiConnect Secure Version9.1 Updater13.1
IvantiConnect Secure Version9.1 Updater14
IvantiConnect Secure Version9.1 Updater14.4
IvantiConnect Secure Version9.1 Updater15
IvantiConnect Secure Version9.1 Updater15.2
IvantiConnect Secure Version9.1 Updater16
IvantiConnect Secure Version9.1 Updater16.1
IvantiConnect Secure Version9.1 Updater17
IvantiConnect Secure Version9.1 Updater17.1
IvantiConnect Secure Version9.1 Updater17.2
IvantiConnect Secure Version9.1 Updater18
IvantiConnect Secure Version9.1 Updater18.1
IvantiConnect Secure Version9.1 Updater18.2
IvantiConnect Secure Version9.1 Updater18.3
IvantiConnect Secure Version9.1 Updater2
IvantiConnect Secure Version9.1 Updater3
IvantiConnect Secure Version9.1 Updater4
IvantiConnect Secure Version9.1 Updater4.1
IvantiConnect Secure Version9.1 Updater4.2
IvantiConnect Secure Version9.1 Updater4.3
IvantiConnect Secure Version9.1 Updater5
IvantiConnect Secure Version9.1 Updater6
IvantiConnect Secure Version9.1 Updater7
IvantiConnect Secure Version9.1 Updater8
IvantiConnect Secure Version9.1 Updater8.1
IvantiConnect Secure Version9.1 Updater8.2
IvantiConnect Secure Version9.1 Updater8.4
IvantiConnect Secure Version9.1 Updater9
IvantiConnect Secure Version9.1 Updater9.1
IvantiConnect Secure Version9.1 Updater9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.15% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
support@hackerone.com 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H