9.1

CVE-2024-39711

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1  allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 22.7
Ivanti ≫ Connect Secure Version 22.7 Update -
Ivanti ≫ Connect Secure Version 22.7 Update r1
Ivanti ≫ Connect Secure Version 22.7 Update r1.1
Ivanti ≫ Connect Secure Version 22.7 Update r1.2
Ivanti ≫ Connect Secure Version 22.7 Update r1.3
Ivanti ≫ Connect Secure Version 22.7 Update r1.4
Ivanti ≫ Connect Secure Version 22.7 Update r1.5
Ivanti ≫ Connect Secure Version 22.7 Update r2
Ivanti ≫ Connect Secure Version 22.7 Update r2.1
Ivanti ≫ Connect Secure Version 22.7 Update r2.2
Ivanti ≫ Policy Secure Version < 22.7
Ivanti ≫ Policy Secure Version 22.7 Update -
Ivanti ≫ Policy Secure Version 22.7 Update r1
Ivanti ≫ Policy Secure Version 22.7 Update r1.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.73% 0.758
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HackerOne 9.1 2.3 6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs
Vendor Advisory