CVE-2023-38551CRLF Injection in Ivanti Connect Secure

CWE-93CRLF Injection3 documents3 sources
Severity
8.2HIGHNVD
EPSS
0.6%
top 30.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 31

Description

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:HExploitability: 2.3 | Impact: 5.3

Affected Packages1 packages

CVEListV5ivanti/connect_secure22.7R222.7R2+2

🔴Vulnerability Details

2
CVEList
CVE-2023-38551: A CRLF Injection vulnerability in Ivanti Connect Secure (92024-05-31
GHSA
GHSA-99x9-vrrc-xxw3: A CRLF Injection vulnerability in Ivanti Connect Secure (92024-05-31
CVE-2023-38551 — CRLF Injection in Ivanti | cvebase