Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 21 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti connect Secure Ivanti policy Secure |
|
| CPEs | cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ivanti
Ivanti connect Secure Ivanti policy Secure |
|
| Metrics |
ssvc
|
Fri, 18 Oct 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2024-10-18T23:06:49.502Z
Updated: 2024-10-21T17:22:47.072Z
Reserved: 2024-06-08T01:04:07.093Z
Link: CVE-2024-37404
Updated: 2024-10-21T17:22:36.364Z
Status : Awaiting Analysis
Published: 2024-10-18T23:15:03.580
Modified: 2024-10-21T17:10:22.857
Link: CVE-2024-37404
No data.