First published: Thu Dec 14 2023(Updated: )
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure | =22.1-r1 | |
Ivanti Connect Secure | =22.1-r6 | |
Ivanti Connect Secure | =22.2 | |
Ivanti Connect Secure | =22.2-r1 | |
Ivanti Connect Secure | =22.3-r1 | |
Ivanti Connect Secure | =22.4-r1 | |
Ivanti Connect Secure | =22.4-r2.1 | |
Ivanti Connect Secure | =22.4-r2.2 | |
Ivanti Connect Secure | =22.5-r1.1 | |
Ivanti Connect Secure | =22.5-r2.1 | |
Ivanti Connect Secure | =22.6 | |
Ivanti Connect Secure | =22.6-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.