CVE-2024-11007
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-11007 is a command injection vulnerability affecting Ivanti Connect Secure versions before 22.7R2.1 and Ivanti Policy Secure versions before 22.7R1.1. An authenticated attacker with administrative privileges can exploit this vulnerability to inject commands, potentially leading to remote code execution and serious system compromise. Ivanti urges users to update their software to the latest versions to mitigate this risk. This issue could enable an attacker to execute arbitrary code on targeted systems, posing a significant threat to data security and confidentiality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Connect Secure
- Ivanti Policy Secure