CVE-2024-21887
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
YesDecision
Descriptions
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Una vulnerabilidad de inyección de comandos en componentes web de Ivanti Connect Secure (9.x, 22.x) e Ivanti Policy Secure (9.x, 22.x) permite a un administrador autenticado enviar solicitudes especialmente manipuladas y ejecutar comandos arbitrarios en el dispositivo.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-03 CVE Reserved
- 2024-01-10 Exploited in Wild
- 2024-01-12 CVE Published
- 2024-01-14 First Exploit
- 2024-01-22 KEV Due Date
- 2024-08-01 CVE Updated
- 2024-11-18 EPSS Updated
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html |
URL | Date | SRC |
---|---|---|
https://github.com/Chocapikk/CVE-2024-21893-to-CVE-2024-21887 | 2024-02-03 | |
https://github.com/Chocapikk/CVE-2024-21887 | 2024-01-17 | |
https://github.com/tucommenceapousser/CVE-2024-21887 | 2024-01-20 | |
https://github.com/imhunterand/CVE-2024-21887 | 2024-02-09 | |
https://github.com/oways/ivanti-CVE-2024-21887 | 2024-01-14 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.0 Search vendor "Ivanti" for product "Connect Secure" and version "9.0" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r10 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11.3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11.4 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r11.5 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r12 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r12.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r13 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r13.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r14 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r15 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r15.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r16 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r16.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r17 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r17.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r18 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r4.3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r5 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r6 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r7 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r8.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r9 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 9.1 Search vendor "Ivanti" for product "Connect Secure" and version "9.1" | r9.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.1 Search vendor "Ivanti" for product "Connect Secure" and version "22.1" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.1 Search vendor "Ivanti" for product "Connect Secure" and version "22.1" | r6 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.2 Search vendor "Ivanti" for product "Connect Secure" and version "22.2" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.2 Search vendor "Ivanti" for product "Connect Secure" and version "22.2" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.3 Search vendor "Ivanti" for product "Connect Secure" and version "22.3" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.4 Search vendor "Ivanti" for product "Connect Secure" and version "22.4" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.4 Search vendor "Ivanti" for product "Connect Secure" and version "22.4" | r2.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.5 Search vendor "Ivanti" for product "Connect Secure" and version "22.5" | r2.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.6 Search vendor "Ivanti" for product "Connect Secure" and version "22.6" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.6 Search vendor "Ivanti" for product "Connect Secure" and version "22.6" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Connect Secure Search vendor "Ivanti" for product "Connect Secure" | 22.6 Search vendor "Ivanti" for product "Connect Secure" and version "22.6" | r2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.0 Search vendor "Ivanti" for product "Policy Secure" and version "9.0" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r10 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r11 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r12 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r13 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r13.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r14 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r15 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r16 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r17 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r18 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r3.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r4 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r4.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r4.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r5 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r6 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r7 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r8 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r8.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r8.2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 9.1 Search vendor "Ivanti" for product "Policy Secure" and version "9.1" | r9 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.1 Search vendor "Ivanti" for product "Policy Secure" and version "22.1" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.1 Search vendor "Ivanti" for product "Policy Secure" and version "22.1" | r6 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.2 Search vendor "Ivanti" for product "Policy Secure" and version "22.2" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.2 Search vendor "Ivanti" for product "Policy Secure" and version "22.2" | r3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.3 Search vendor "Ivanti" for product "Policy Secure" and version "22.3" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.3 Search vendor "Ivanti" for product "Policy Secure" and version "22.3" | r3 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.4 Search vendor "Ivanti" for product "Policy Secure" and version "22.4" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.4 Search vendor "Ivanti" for product "Policy Secure" and version "22.4" | r2 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.4 Search vendor "Ivanti" for product "Policy Secure" and version "22.4" | r2.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.5 Search vendor "Ivanti" for product "Policy Secure" and version "22.5" | r1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.5 Search vendor "Ivanti" for product "Policy Secure" and version "22.5" | r2.1 |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Policy Secure Search vendor "Ivanti" for product "Policy Secure" | 22.6 Search vendor "Ivanti" for product "Policy Secure" and version "22.6" | r1 |
Affected
|