CVE-2024-10644: Code Injection
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10644?
CVE-2024-10644 is classified as a critical vulnerability due to its potential for remote code execution by authenticated attackers with admin privileges.
How do I fix CVE-2024-10644?
To fix CVE-2024-10644, upgrade Ivanti Connect Secure to version 22.7R2.4 or later and Ivanti Policy Secure to version 22.7R1.3 or later.
Who is affected by CVE-2024-10644?
CVE-2024-10644 affects users of Ivanti Connect Secure versions prior to 22.7R2.4 and Ivanti Policy Secure versions prior to 22.7R1.3.
What type of vulnerability is CVE-2024-10644?
CVE-2024-10644 is a code injection vulnerability that allows remote code execution.
Can CVE-2024-10644 be exploited remotely?
Yes, CVE-2024-10644 can be exploited remotely by authenticated attackers with admin privileges.