Ivanti Connect Secure vulnerabilities
130 known vulnerabilities affecting ivanti/connect_secure.
Total CVEs
130
CISA KEV
14
actively exploited
Public exploits
10
Exploited in wild
12
Severity breakdown
CRITICAL15HIGH67MEDIUM46LOW2
Vulnerabilities
Page 3 of 7
CVE-2024-38655HIGHCVSS 7.2fixed in 22.7v22.7+2 more2024-11-13
CVE-2024-38655 [HIGH] CWE-88 CVE-2024-38655: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy S
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-37400HIGHCVSS 7.5fixed in 22.7v22.7+1 more2024-11-13
CVE-2024-37400 [HIGH] CWE-125 CVE-2024-37400: An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticat
An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.
cvelistv5nvd
CVE-2024-39709HIGHCVSS 7.8fixed in 9.1≥ 21.9, < 22.6+3 more2024-11-13
CVE-2024-39709 [HIGH] CWE-732 CVE-2024-39709: Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx)
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
cvelistv5nvd
CVE-2024-38649HIGHCVSS 7.5fixed in 9.1≥ 21.9, < 22.7+3 more2024-11-13
CVE-2024-38649 [HIGH] CWE-125 CVE-2024-38649: An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.
cvelistv5nvd
CVE-2024-8495HIGHCVSS 7.5fixed in 22.7v22.72024-11-12
CVE-2024-8495 [HIGH] CWE-476 CVE-2024-8495: A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
nvd
CVE-2024-47906HIGHCVSS 7.8fixed in 9.1fixed in 22.7+2 more2024-11-12
CVE-2024-47906 [HIGH] CWE-267 CVE-2024-47906: Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1R
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.
cvelistv5nvd
CVE-2024-11007HIGHCVSS 7.2fixed in 22.7v22.72024-11-12
CVE-2024-11007 [HIGH] CWE-78 CVE-2024-11007: Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Iva
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
nvd
CVE-2024-11005HIGHCVSS 7.2fixed in 9.1fixed in 22.7+1 more2024-11-12
CVE-2024-11005 [HIGH] CWE-78 CVE-2024-11005: Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Iva
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
nvd
CVE-2024-11006HIGHCVSS 7.2fixed in 9.1fixed in 22.7+1 more2024-11-12
CVE-2024-11006 [HIGH] CWE-78 CVE-2024-11006: Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Iva
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
nvd
CVE-2024-47907HIGHCVSS 7.5fixed in 22.7v22.72024-11-12
CVE-2024-47907 [HIGH] CWE-121 CVE-2024-47907: A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a rem
A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
nvd
CVE-2024-9420HIGHCVSS 8.8fixed in 9.1≥ 21.9, < 22.7+2 more2024-11-12
CVE-2024-9420 [HIGH] CWE-416 CVE-2024-9420: A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9
and Ivanti Policy S
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9
and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
nvd
CVE-2024-11004MEDIUMCVSS 6.1fixed in 22.7v22.72024-11-12
CVE-2024-11004 [MEDIUM] CWE-79 CVE-2024-11004: Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before versi
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
nvd
CVE-2024-47909MEDIUMCVSS 4.9fixed in 22.7v22.72024-11-12
CVE-2024-47909 [MEDIUM] CWE-121 CVE-2024-47909: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Sec
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
nvd
CVE-2024-47905MEDIUMCVSS 4.9fixed in 22.7v22.72024-11-12
CVE-2024-47905 [MEDIUM] CWE-121 CVE-2024-47905: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Sec
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
nvd
CVE-2024-37404HIGHCVSS 8.8PoCfixed in 9.1≥ 22.3, < 22.7+4 more2024-10-18
CVE-2024-37404 [HIGH] CVE-2024-37404: Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9,
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
cvelistv5nvd
CVE-2023-38551HIGHCVSS 8.2≥ 22.7R2, < 22.7R2≥ 22.5R2.2, < 22.5R2.2+1 more2024-05-31
CVE-2023-38551 [HIGH] CWE-93 CVE-2023-38551: A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-pri
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
cvelistv5nvd
CVE-2024-29205HIGHCVSS 7.5≥ 9.1R18.5, < 9.1R18.5≥ 22.6R2.3, < 22.6R2.3+13 more2024-04-25
CVE-2024-29205 [HIGH] CWE-703 CVE-2024-29205: An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti
An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.
cvelistv5nvd
CVE-2024-21894CRITICALCVSS 9.8v9.1v22.1+18 more2024-04-04
CVE-2024-21894 [CRITICAL] CWE-787 CVE-2024-21894: A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Pol
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code
cvelistv5nvd
CVE-2024-22053HIGHCVSS 8.2v9.1v22.1+18 more2024-04-04
CVE-2024-22053 [HIGH] CWE-787 CVE-2024-22053: A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
22.x) and Ivanti Pol
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.
cvelistv5nvd
CVE-2024-22052HIGHCVSS 7.5v9.1v22.1+18 more2024-04-04
CVE-2024-22052 [HIGH] CWE-476 CVE-2024-22052: A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
cvelistv5nvd