CVE-2023-38551: CRLF Injection
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38551?
CVE-2023-38551 is considered a high severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2023-38551?
To fix CVE-2023-38551, update Ivanti Connect Secure to the latest version that addresses this vulnerability.
Which versions of Ivanti Connect Secure are affected by CVE-2023-38551?
CVE-2023-38551 affects Ivanti Connect Secure versions 9.x and 22.x up to version 10.0 and 23.0 respectively.
What are the potential impacts of exploiting CVE-2023-38551?
Exploiting CVE-2023-38551 may allow an attacker to execute malicious scripts in the context of a victim’s browser.
Who is at risk due to CVE-2023-38551?
Authenticated high-privileged users of Ivanti Connect Secure could potentially exploit CVE-2023-38551, placing other users at risk.