CVE-2024-21887
קריטית 9.1 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
מדדים
- CVSS 3.1
-
9.1 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-77
מוצרים מושפעים
ivanti: connect secure; ivanti: policy secure
קישורים
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2… Vendor Advisory
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2… Vendor Advisory
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthentica… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthentica… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource