Ivanti Ics vulnerabilities
5 known vulnerabilities affecting ivanti/ics.
Total CVEs
5
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH4
Vulnerabilities
Page 1 of 1
CVE-2024-22024HIGHCVSS 8.3PoC≥ 9.1R14.5, < 9.1R14.5≥ 9.1R17.3, < 9.1R17.3+10 more2024-02-13
CVE-2024-22024 [HIGH] CWE-611 CVE-2024-22024: An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
cvelistv5nvd
CVE-2024-21888HIGHCVSS 8.8≥ 9.1R18, ≤ 9.1R18≥ 22.6R2, ≤ 22.6R22024-01-31
CVE-2024-21888 [HIGH] CWE-269 CVE-2024-21888: A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivant
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.
cvelistv5nvd
CVE-2024-21893HIGHCVSS 8.2KEVPoC≥ 9.1R18, ≤ 9.1R18≥ 22.6R2, ≤ 22.6R22024-01-31
CVE-2024-21893 [HIGH] CWE-918 CVE-2024-21893: A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
cvelistv5nvd
CVE-2024-21887CRITICALCVSS 9.1KEVPoC≥ 9.1R18, ≤ 9.1R18≥ 22.6R2, ≤ 22.6R22024-01-12
CVE-2024-21887 [CRITICAL] CWE-77 CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
cvelistv5nvd
CVE-2023-46805HIGHCVSS 8.2KEVPoC≥ 9.1R18, ≤ 9.1R18≥ 22.6R2, ≤ 22.6R22024-01-12
CVE-2023-46805 [HIGH] CWE-287 CVE-2023-46805: An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Polic
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
cvelistv5nvd