CVE-2024-21887
KEV
🔴 Łataj teraz
Wstrzyknięcie poleceń w Ivanti Connect Secure umożliwia wykonanie dowolnych komend przez administratora.
CVSS
9.1
EPSS
100.0%
Exploit
weaponized
Vendor
ivanti
Opis źródłowy (NVD)
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
exploit rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 100.0% |
| Opublikowano (NVD) | 2024-01-12 17:15:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:30 UTC |
Referencje
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html (support@hackerone.com) [Exploit, Third Party Advisory, VDB Entry]
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US (support@hackerone.com) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21887 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]