CVE-2024-39710: Critical severity ivanti pulse connect secure vulnerability
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39710?
CVE-2024-39710 is classified as a critical vulnerability due to its potential for remote code execution by an authenticated attacker.
How do I fix CVE-2024-39710?
To fix CVE-2024-39710, upgrade Ivanti Connect Secure to version 22.7R2.1 or 9.1R18.7 and Ivanti Policy Secure to version 22.7R1.1.
Who is affected by CVE-2024-39710?
CVE-2024-39710 affects users of Ivanti Connect Secure versions prior to 22.7R2.1 and 9.1R18.7, and Ivanti Policy Secure versions prior to 22.7R1.1.
What type of attack can CVE-2024-39710 facilitate?
CVE-2024-39710 can facilitate remote code execution attacks by an authenticated user with admin privileges.
What are the potential risks of CVE-2024-39710?
The risks associated with CVE-2024-39710 include unauthorized remote access, data breach, and system compromise.