A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
CVE ID: CVE-2024-21887
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.1
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vendor: Ivanti
Product: ICS
http/cves/2024/CVE-2024-21887.yaml
EPSS Score: 97.37% (probability of being exploited)
EPSS Percentile: 99.96% (scored less or equal to compared to others)
EPSS Date: 2025-03-05 (when was this score calculated)