CVE-2024-13830: XSS
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13830?
CVE-2024-13830 is considered a high-severity vulnerability due to its potential to allow remote unauthenticated attackers to gain admin privileges.
How do I fix CVE-2024-13830?
To fix CVE-2024-13830, upgrade Ivanti Connect Secure to version 22.7R2.6 or later and Ivanti Policy Secure to version 22.7R1.3 or later.
What systems are affected by CVE-2024-13830?
CVE-2024-13830 affects Ivanti Connect Secure versions prior to 22.7R2.6 and Ivanti Policy Secure versions prior to 22.7R1.3.
Does CVE-2024-13830 require user interaction to exploit?
Yes, CVE-2024-13830 requires user interaction for the exploitation of the reflected XSS vulnerability.
Can CVE-2024-13830 lead to data breaches?
Yes, exploitation of CVE-2024-13830 can potentially lead to unauthorized access and data breaches due to the ability to obtain admin privileges.