CVE-2024-11007

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 78

Summary

CVE-2024-11007 is a command injection vulnerability affecting Ivanti Connect Secure versions before 22.7R2.1 and Ivanti Policy Secure versions before 22.7R1.1. An authenticated attacker with administrative privileges can exploit this vulnerability to inject commands, potentially leading to remote code execution and serious system compromise. Ivanti urges users to update their software to the latest versions to mitigate this risk. This issue could enable an attacker to execute arbitrary code on targeted systems, posing a significant threat to data security and confidentiality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Connect Secure
  • Ivanti Policy Secure