CVE-2024-21887criticalKEVEXPLOITRANSOMWAREZERO DAYSecurin Validate-Ready
Security Update for Ivanti Connect Secure and Ivanti Policy Secure Gateways
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Vulnerability Type
Code Injection
Impact Type
Code Execution
Vector
NETWORK
Affected Vendors
ivanti +1 more
Securin Risk Score
CVSS: 9.1
Vulnerability Timeline
- CVE Published
- 1st Exploit Published
- Securin Predicted
- Securin KEV Published
- CISA KEV Published
- NVD Published
- Securin Predicted → NVD Latency: 9 days
- Securin Predicted → CISA Latency: Up to 1 Day
- Securin Predicted → Exploit Latency: 7 days
Threat Intelligence Summary
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Weaknesses
—
Threats
22
Threat Actor Associations
—
References
Unlock the details for this CVE
Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.
Unlock with Securin