Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
2024-10-18T23:15:03.580
2025-09-23T02:10:06.103
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ivanti | connect_secure | < 9.1 | Yes |
| Application | ivanti | connect_secure | < 22.7 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 9.1 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | connect_secure | 22.7 | Yes |
| Application | ivanti | policy_secure | < 22.7 | Yes |
| Application | ivanti | policy_secure | 22.7 | Yes |
| Application | ivanti | policy_secure | 22.7 | Yes |