CVE-2024-21887: Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Other sources
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
— CISA
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What are the potential impacts of CVE-2024-21887?
CVE-2024-21887 allows authenticated administrators to execute arbitrary commands on the appliance, potentially leading to a complete compromise of the system.
Who is vulnerable to CVE-2024-21887?
CVE-2024-21887 affects authenticated administrators of Ivanti Connect Secure and Ivanti Policy Secure versions 9.x and 22.x.
What is the recommended mitigation for CVE-2024-21887?
To mitigate CVE-2024-21887, it is recommended to update Ivanti Connect Secure and Policy Secure to the latest patched versions released by Ivanti.
How can I verify if I am using a vulnerable version regarding CVE-2024-21887?
You can verify the version of Ivanti Connect Secure or Policy Secure you are using by checking the version number in the application settings or documentation.
Is CVE-2024-21887 actively being exploited?
Yes, CVE-2024-21887 is reported to be actively exploited in the wild, making immediate action necessary for affected systems.