← Back

CVE-2024-38657

nvd nist
Published: Feb 21, 2025Modified: Jul 9, 2025

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.

Affected (17)

2 products
Connect Secure
Policy Secure
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 22.7
Version 22.7
Version 22.7 r1.1
Version 22.7 r1.2
Version 22.7 r1.3
Version 22.7 r1.4
Version 22.7 r1.5
Version 22.7 r1
Version 22.7 r2.1
Version 22.7 r2.2
Version 22.7 r2.3
Version 22.7 r2
Ivanti
Before 22.7
Version 22.7
Version 22.7 r1.1
Version 22.7 r1.2
Version 22.7 r1

Timeline

No history available yet.