Zurück zur CVE-Übersicht
CVE-2024-21887
CRITICAL(9.1)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Risk Signal Score83/100 — KRITISCH
- CVSS 9.1 — Kritisch
- EPSS 100% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
100%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.1
Technische Schwere
Beschreibung
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Referenzen
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticate...
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-202...
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticate...
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-202...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-...