Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-47906


Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.


Published

2024-11-12T16:15:22.670

Last Modified

2025-01-17T20:27:14.100

Status

Analyzed

Source

3c1d8aa1-5a33-4ea4-8992-aadd6440af75

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-267
    CWE-426
  • Type: Primary
    CWE-426
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti connect_secure < 9.1 Yes
Application ivanti connect_secure < 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti connect_secure 22.7 Yes
Application ivanti policy_secure < 9.1 Yes
Application ivanti policy_secure < 22.7 Yes
Application ivanti policy_secure 22.7 Yes
Application ivanti policy_secure 22.7 Yes

References