CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an...

9.1 CVSS

Description

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

Classification

CVE ID: CVE-2024-21887

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.1

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products

Vendor: Ivanti

Product: ICS

Nuclei Template

http/cves/2024/CVE-2024-21887.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 97.37% (probability of being exploited)

EPSS Percentile: 99.96% (scored less or equal to compared to others)

EPSS Date: 2025-03-05 (when was this score calculated)

References

https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html

Timeline