CVE-2024-39710
CVSS 3.0 Score 9.1 of 10 (critical)
Details
Summary
CVE-2024-39710 is a newly disclosed vulnerability affecting Ivanti Connect Secure versions before 22.7R2 and 9.1R18.7, as well as Ivanti Policy Secure before version 22.7R1.1. This issue permits a remote, authenticated attacker with administrative privileges to inject arguments and ultimately execute arbitrary code. By exploiting this vulnerability, an attacker can gain unauthorized control over affected systems. This poses a significant risk for organizations using these Ivanti products and highlights the importance of timely software updates to mitigate known security vulnerabilities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.