A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Pulse Pulse Secure Policy | — | Mitigation with XML import | Jan 15, 2023 | Jan 10, 2023 |
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 22.4R2.3Update Ivanti Connect Secure to version 22.2R4.1Update Ivanti Connect Secure to version 22.1R6.1Update Ivanti Connect Secure to version 22.3R1.1Update Ivanti Connect Secure to version 9.1R18.4Update Ivanti Connect Secure to version 22.6R2.2Update Ivanti Connect Secure to version 22.5R2.3 | May 21, 2024 | Jan 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub