CVE-2024-11006: OS Command Injection
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11006?
CVE-2024-11006 has been rated as critical because it allows remote code execution by an authenticated attacker with admin privileges.
How do I fix CVE-2024-11006?
To fix CVE-2024-11006, update Ivanti Connect Secure to version 22.7R2.1 or later, and Ivanti Policy Secure to version 22.7R1.1 or later.
Who is affected by CVE-2024-11006?
CVE-2024-11006 affects users of Ivanti Connect Secure and Ivanti Policy Secure versions prior to the stated fixed versions.
What does CVE-2024-11006 exploit?
CVE-2024-11006 exploits a command injection vulnerability that allows remote authenticated attackers to execute arbitrary code.
Is CVE-2024-11006 applicable to all Ivanti versions?
CVE-2024-11006 is not applicable to Ivanti versions 9.1Rx.