THREAT OPS › Threat News › [NVD] CVE-2024-21887 (CRITICAL 9.1) — A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
[NVD] CVE-2024-21887 (CRITICAL 9.1) — A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
CVE-2024-21887 CVSS: 9.1 CRITICAL Published: 2024-01-12T17:15:10.017
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Indicators of compromise
- CVE-2024-21887cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-21887