Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-21887


A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.


Published

2024-01-12T17:15:10.017

Last Modified

2025-02-12T19:55:33.273

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 22.1 Yes
Application ivanti connect_secure 22.1 Yes
Application ivanti connect_secure 22.2 Yes
Application ivanti connect_secure 22.2 Yes
Application ivanti connect_secure 22.3 Yes
Application ivanti connect_secure 22.4 Yes
Application ivanti connect_secure 22.4 Yes
Application ivanti connect_secure 22.5 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 22.1 Yes
Application ivanti policy_secure 22.1 Yes
Application ivanti policy_secure 22.2 Yes
Application ivanti policy_secure 22.2 Yes
Application ivanti policy_secure 22.3 Yes
Application ivanti policy_secure 22.3 Yes
Application ivanti policy_secure 22.4 Yes
Application ivanti policy_secure 22.4 Yes
Application ivanti policy_secure 22.4 Yes
Application ivanti policy_secure 22.5 Yes
Application ivanti policy_secure 22.5 Yes
Application ivanti policy_secure 22.6 Yes

References