CVE-2023-41720Ivanti Connect Secure vulnerability

4 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 68.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 14

Description

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5ivanti/connect_secure22.6.122.6.1
NVDivanti/connect_secure6 versions+5

🔴Vulnerability Details

2
CVEList
CVE-2023-41720: A vulnerability exists on all versions of Ivanti Connect Secure below 222023-12-14
GHSA
GHSA-rphc-vh34-9jmw: A vulnerability exists on all versions of Ivanti Connect Secure below 222023-12-14

📋Vendor Advisories

1
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Go) — CVE-2022-417202023-01-15
CVE-2023-41720 — Ivanti Connect Secure vulnerability | cvebase