CVE-2024-11005: OS Command Injection
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11005?
CVE-2024-11005 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-11005?
To fix CVE-2024-11005, upgrade Ivanti Connect Secure or Ivanti Policy Secure to versions 22.7R2.1 or 22.7R1.1, respectively.
Who is affected by CVE-2024-11005?
CVE-2024-11005 affects remote authenticated users with admin privileges on Ivanti Connect Secure and Ivanti Policy Secure versions below the specified patches.
What products are impacted by CVE-2024-11005?
CVE-2024-11005 impacts Ivanti Connect Secure and Ivanti Policy Secure prior to versions 22.7R2.1 and 22.7R1.1, respectively.
Can CVE-2024-11005 be exploited without authentication?
No, CVE-2024-11005 requires the attacker to have authenticated admin access to exploit the vulnerability.