8.8

CVE-2024-21888

Warnung
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. 
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version 9.0 Update -
Ivanti ≫ Connect Secure Version 9.0 Update r1
Ivanti ≫ Connect Secure Version 9.0 Update r2
Ivanti ≫ Connect Secure Version 9.0 Update r2.1
Ivanti ≫ Connect Secure Version 9.0 Update r3
Ivanti ≫ Connect Secure Version 9.0 Update r3.1
Ivanti ≫ Connect Secure Version 9.0 Update r3.2
Ivanti ≫ Connect Secure Version 9.0 Update r3.3
Ivanti ≫ Connect Secure Version 9.0 Update r3.5
Ivanti ≫ Connect Secure Version 9.0 Update r4
Ivanti ≫ Connect Secure Version 9.0 Update r4.1
Ivanti ≫ Connect Secure Version 9.0 Update r5.0
Ivanti ≫ Connect Secure Version 9.0 Update r6.0
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r10
Ivanti ≫ Connect Secure Version 9.1 Update r11
Ivanti ≫ Connect Secure Version 9.1 Update r11.3
Ivanti ≫ Connect Secure Version 9.1 Update r11.4
Ivanti ≫ Connect Secure Version 9.1 Update r11.5
Ivanti ≫ Connect Secure Version 9.1 Update r12
Ivanti ≫ Connect Secure Version 9.1 Update r12.1
Ivanti ≫ Connect Secure Version 9.1 Update r13
Ivanti ≫ Connect Secure Version 9.1 Update r13.1
Ivanti ≫ Connect Secure Version 9.1 Update r14
Ivanti ≫ Connect Secure Version 9.1 Update r15
Ivanti ≫ Connect Secure Version 9.1 Update r15.2
Ivanti ≫ Connect Secure Version 9.1 Update r16
Ivanti ≫ Connect Secure Version 9.1 Update r16.1
Ivanti ≫ Connect Secure Version 9.1 Update r17
Ivanti ≫ Connect Secure Version 9.1 Update r17.1
Ivanti ≫ Connect Secure Version 9.1 Update r18
Ivanti ≫ Connect Secure Version 9.1 Update r18.1
Ivanti ≫ Connect Secure Version 9.1 Update r18.2
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 9.1 Update r8.1
Ivanti ≫ Connect Secure Version 9.1 Update r8.2
Ivanti ≫ Connect Secure Version 9.1 Update r9
Ivanti ≫ Connect Secure Version 9.1 Update r9.1
Ivanti ≫ Connect Secure Version 21.9 Update r1
Ivanti ≫ Connect Secure Version 21.12 Update r1
Ivanti ≫ Connect Secure Version 22.1 Update r1
Ivanti ≫ Connect Secure Version 22.1 Update r6
Ivanti ≫ Connect Secure Version 22.2 Update -
Ivanti ≫ Connect Secure Version 22.2 Update r1
Ivanti ≫ Connect Secure Version 22.3 Update r1
Ivanti ≫ Connect Secure Version 22.4 Update r1
Ivanti ≫ Connect Secure Version 22.4 Update r2.1
Ivanti ≫ Connect Secure Version 22.6 Update -
Ivanti ≫ Connect Secure Version 22.6 Update r1
Ivanti ≫ Connect Secure Version 22.6 Update r2
Ivanti ≫ Connect Secure Version 22.6 Update r2.1
Ivanti ≫ Policy Secure Version 9.0 Update -
Ivanti ≫ Policy Secure Version 9.0 Update r1
Ivanti ≫ Policy Secure Version 9.0 Update r2
Ivanti ≫ Policy Secure Version 9.0 Update r2.1
Ivanti ≫ Policy Secure Version 9.0 Update r3
Ivanti ≫ Policy Secure Version 9.0 Update r3.1
Ivanti ≫ Policy Secure Version 9.0 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update -
Ivanti ≫ Policy Secure Version 9.1 Update r1
Ivanti ≫ Policy Secure Version 9.1 Update r10
Ivanti ≫ Policy Secure Version 9.1 Update r11
Ivanti ≫ Policy Secure Version 9.1 Update r12
Ivanti ≫ Policy Secure Version 9.1 Update r13
Ivanti ≫ Policy Secure Version 9.1 Update r13.1
Ivanti ≫ Policy Secure Version 9.1 Update r14
Ivanti ≫ Policy Secure Version 9.1 Update r15
Ivanti ≫ Policy Secure Version 9.1 Update r16
Ivanti ≫ Policy Secure Version 9.1 Update r17
Ivanti ≫ Policy Secure Version 9.1 Update r18
Ivanti ≫ Policy Secure Version 9.1 Update r18.1
Ivanti ≫ Policy Secure Version 9.1 Update r18.2
Ivanti ≫ Policy Secure Version 9.1 Update r2
Ivanti ≫ Policy Secure Version 9.1 Update r3
Ivanti ≫ Policy Secure Version 9.1 Update r3.1
Ivanti ≫ Policy Secure Version 9.1 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update r4.1
Ivanti ≫ Policy Secure Version 9.1 Update r4.2
Ivanti ≫ Policy Secure Version 9.1 Update r4.3
Ivanti ≫ Policy Secure Version 9.1 Update r5
Ivanti ≫ Policy Secure Version 9.1 Update r6
Ivanti ≫ Policy Secure Version 9.1 Update r7
Ivanti ≫ Policy Secure Version 9.1 Update r8
Ivanti ≫ Policy Secure Version 9.1 Update r8.1
Ivanti ≫ Policy Secure Version 9.1 Update r8.2
Ivanti ≫ Policy Secure Version 9.1 Update r9
Ivanti ≫ Policy Secure Version 22.1 Update r1
Ivanti ≫ Policy Secure Version 22.1 Update r6
Ivanti ≫ Policy Secure Version 22.2 Update r1
Ivanti ≫ Policy Secure Version 22.2 Update r3
Ivanti ≫ Policy Secure Version 22.3 Update r1
Ivanti ≫ Policy Secure Version 22.3 Update r3
Ivanti ≫ Policy Secure Version 22.4 Update r1
Ivanti ≫ Policy Secure Version 22.4 Update r2
Ivanti ≫ Policy Secure Version 22.4 Update r2.1
Ivanti ≫ Policy Secure Version 22.5 Update r1
Ivanti ≫ Policy Secure Version 22.6 Update r1
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 86.81% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
HackerOne 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US
Vendor Advisory