216.73.217.22

CVE-2024-21887

· Published 10/01/2024 01:00 · Modified 27/05/2026 21:40 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2024-21887

Essential information

Published
10/01/2024 01:00
Modified
27/05/2026 21:40
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

NVD status

NVD
View on NVD