← Back

CVE-2023-41720

nvd nist
Published: Dec 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.

Affected (12)

1 product
Connect Secure
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 22.1 r1
Version 22.1 r6
Version 22.2
Version 22.2 r1
Version 22.3 r1
Version 22.4 r1
Version 22.4 r2.1
Version 22.4 r2.2
Version 22.5 r1.1
Version 22.5 r2.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 22.6
Version 22.6 r1

Timeline

No history available yet.