Vulnerability Description
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | 9.0 |
| Ivanti | Policy Secure | 9.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-UnauthenticateExploitThird Party AdvisoryVDB Entry
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-202Vendor Advisory
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-UnauthenticateExploitThird Party AdvisoryVDB Entry
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-202Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-US Government Resource
FAQ
What is CVE-2024-21887?
CVE-2024-21887 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests ...
How severe is CVE-2024-21887?
CVE-2024-21887 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-21887?
Check the references section above for vendor advisories and patch information. Affected products include: Ivanti Connect Secure, Ivanti Policy Secure.