PT-2024-16696 · Ivanti · Ivanti Policy Secure+1

Published

2024-11-12

·

Updated

2024-11-22

·

CVE-2024-11007

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Connect Secure versions prior to 22.7R2.1 Ivanti Policy Secure versions prior to 22.7R1.1
Description The issue allows a remote authenticated attacker with admin privileges to achieve remote code execution through command injection. This is a critical vulnerability affecting Ivanti products.
Recommendations For Ivanti Connect Secure versions prior to 22.7R2.1, update to version 22.7R2.1 or later. For Ivanti Policy Secure versions prior to 22.7R1.1, update to version 22.7R1.1 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-11007

Affected Products

Ivanti Connect Secure
Ivanti Policy Secure