CVE-2022-21828: High severity ivanti incapptic connect vulnerability
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-21828.
What is the severity of CVE-2022-21828?
The severity of CVE-2022-21828 is high with a CVSS score of 7.2.
Which software versions are affected by CVE-2022-21828?
CVE-2022-21828 affects Incapptic Connect versions 1.35.3 to 1.40.0.
How can an attacker exploit CVE-2022-21828?
An attacker with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using an unspecified attack vector.
How can I fix CVE-2022-21828?
To fix CVE-2022-21828, it is recommended to upgrade to a secure version of Incapptic Connect (1.40.1 or later) provided by Ivanti.