CVE-2023-38551 — CRLF Injection in Ivanti Connect Secure
Severity
8.2HIGHNVD
EPSS
0.6%
top 30.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 31
Description
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:HExploitability: 2.3 | Impact: 5.3