PT-2024-28646 · Ivanti · Ivanti Policy Secure+1

Published

2024-11-11

·

Updated

2025-07-16

·

CVE-2024-39709

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Connect Secure versions prior to 22.6R2 Ivanti Policy Secure versions prior to 22.7R1
Description The issue is related to incorrect file permissions in Ivanti Connect Secure and Ivanti Policy Secure, allowing a local authenticated attacker to escalate their privileges.
Recommendations For Ivanti Connect Secure versions prior to 22.6R2, update to version 22.6R2 or later to resolve the issue. For Ivanti Policy Secure versions prior to 22.7R1, update to version 22.7R1 or later to resolve the issue.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01314
CVE-2024-39709

Affected Products

Ivanti Connect Secure
Ivanti Policy Secure