← Back

CVE-2023-41719

nvd nist
Published: Dec 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.

Affected (53)

1 product
Connect Secure
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 21.12 r1
Version 21.9 r1
Version 22.1 r1
Version 22.1 r6
Version 22.2 r1
Version 22.3 r1
Version 22.4 r1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 22.5 r1.1
Version 22.5 r2.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 22.6
Version 22.6 r1
Configuration D
42 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 9.1 r10.2
Version 9.1 r10
Version 9.1 r11.1
Version 9.1 r11.3
Version 9.1 r11.4
Version 9.1 r11.5
Version 9.1 r11
Version 9.1 r12.1
Version 9.1 r12.2
Version 9.1 r12
Version 9.1 r13.1
Version 9.1 r13
Version 9.1 r14.4
Version 9.1 r14
Version 9.1 r15.2
Version 9.1 r15
Version 9.1 r16.1
Version 9.1 r16
Version 9.1 r17.1
Version 9.1 r17.2
Version 9.1 r17
Version 9.1 r18.1
Version 9.1 r18.2
Version 9.1 r18.3
Version 9.1 r18
Version 9.1 r1
Version 9.1 r2
Version 9.1 r3
Version 9.1 r4.1
Version 9.1 r4.2
Version 9.1 r4.3
Version 9.1 r4
Version 9.1 r5
Version 9.1 r6
Version 9.1 r7
Version 9.1 r8.1
Version 9.1 r8.2
Version 9.1 r8.4
Version 9.1 r8
Version 9.1 r9.1
Version 9.1 r9.2
Version 9.1 r9

Timeline

No history available yet.