CVE-2024-11634: Command Injection
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11634?
CVE-2024-11634 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-11634?
To fix CVE-2024-11634, upgrade Ivanti Connect Secure to version 22.7R2.3 or later, and Ivanti Policy Secure to version 22.7R1.2 or later.
Who can exploit CVE-2024-11634?
CVE-2024-11634 can be exploited by remote authenticated attackers with admin privileges.
Which versions of Ivanti software are affected by CVE-2024-11634?
CVE-2024-11634 affects Ivanti Connect Secure versions before 22.7R2.3 and Ivanti Policy Secure versions before 22.7R1.2.
What type of vulnerability is CVE-2024-11634?
CVE-2024-11634 is a command injection vulnerability that allows attackers to execute arbitrary code remotely.