CVE-2024-11004: XSS
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11004?
CVE-2024-11004 is considered a high severity vulnerability due to allowing remote unauthenticated attackers to gain admin privileges.
How do I fix CVE-2024-11004?
To fix CVE-2024-11004, upgrade Ivanti Connect Secure to version 22.7R2.1 or Ivanti Policy Secure to version 22.7R1.1 or later.
What software is affected by CVE-2024-11004?
CVE-2024-11004 affects Ivanti Connect Secure versions prior to 22.7R2.1 and Ivanti Policy Secure versions before 22.7R1.1.
Does CVE-2024-11004 require user interaction?
Yes, CVE-2024-11004 requires user interaction for exploitation.
Can CVE-2024-11004 lead to data breaches?
Yes, CVE-2024-11004 can potentially lead to unauthorized access and data breaches due to the ability to obtain admin privileges.