Skip to content
    CVE-2024-21887criticalKEVEXPLOITRANSOMWAREZERO DAYSecurin Validate-Ready

    Security Update for Ivanti Connect Secure and Ivanti Policy Secure Gateways

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    Vulnerability Type
    Code Injection
    Impact Type
    Code Execution
    Vector
    NETWORK
    Affected Vendors
    ivanti +1 more
    9.05CriticalSecurin Risk Score
    CVSS: 9.1

    Vulnerability Timeline

    1. CVE Published
    2. 1st Exploit Published
    3. Securin Predicted
    4. Securin KEV Published
    5. CISA KEV Published
    6. NVD Published
    • Securin Predicted → NVD Latency: 9 days
    • Securin Predicted → CISA Latency: Up to 1 Day
    • Securin Predicted → Exploit Latency: 7 days

    Threat Intelligence Summary

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    Weaknesses
    Threats
    22
    Threat Actor Associations

    References

    CVE

    Exploit

    Unlock the details for this CVE

    Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.

    Unlock with Securin