THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-21887 (CRITICAL 9.1) — A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

[NVD] CVE-2024-21887 (CRITICAL 9.1) — A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

lownvdPublished 2024-01-12

CVE-2024-21887 CVSS: 9.1 CRITICAL Published: 2024-01-12T17:15:10.017

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-21887