CVE-2024-11634Command Injection in Ivanti Connect Secure

CWE-77Command Injection3 documents3 sources
Severity
7.2HIGHNVD
CNA9.1
EPSS
12.5%
top 6.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10

Description

Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDivanti/policy_secure< 22.7+1
NVDivanti/connect_secure< 22.7+1

🔴Vulnerability Details

2
GHSA
GHSA-qr6x-pgq2-jjxh: Command injection in Ivanti Connect Secure before version 222024-12-10
CVEList
CVE-2024-11634: Command injection in Ivanti Connect Secure before version 222024-12-10
CVE-2024-11634 — Command Injection in Ivanti | cvebase