← Back

CVE-2024-37404

nvd nist
Published: Oct 18, 2024Modified: Sep 23, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

Affected (59)

2 products
Connect Secure
Policy Secure
Configuration A
59 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 9.1
From 22.3 to 22.7
Version 22.7
Version 22.7 r1.1
Version 22.7 r1.2
Version 22.7 r1.3
Version 22.7 r1.4
Version 22.7 r1.5
Version 22.7 r1
Version 22.7 r2.1
Version 22.7 r2
Version 9.1 r10.2
Version 9.1 r10
Version 9.1 r11.0
Version 9.1 r11.1
Version 9.1 r11.3
Version 9.1 r11.4
Version 9.1 r11.5
Version 9.1 r11
Version 9.1 r12.1
Version 9.1 r12.2
Version 9.1 r12
Version 9.1 r13.1
Version 9.1 r13
Version 9.1 r14.4
Version 9.1 r14
Version 9.1 r15.2
Version 9.1 r15
Version 9.1 r16.1
Version 9.1 r16
Version 9.1 r17.1
Version 9.1 r17.2
Version 9.1 r17
Version 9.1 r18.1
Version 9.1 r18.2
Version 9.1 r18.3
Version 9.1 r18.7
Version 9.1 r18.8
Version 9.1 r18
Version 9.1 r1
Version 9.1 r2
Version 9.1 r3
Version 9.1 r4.1
Version 9.1 r4.2
Version 9.1 r4.3
Version 9.1 r4
Version 9.1 r5
Version 9.1 r6
Version 9.1 r7
Version 9.1 r8.1
Version 9.1 r8.2
Version 9.1 r8.4
Version 9.1 r8
Version 9.1 r9.1
Version 9.1 r9.2
Version 9.1 r9
Ivanti
Before 22.7
Version 22.7
Version 22.7 r1

Timeline

No history available yet.