CVE-2024-39712: Critical severity ivanti pulse connect secure vulnerability
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.7 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39712?
CVE-2024-39712 has a critical severity rating due to its potential for remote code execution by authenticated attackers.
How do I fix CVE-2024-39712?
To fix CVE-2024-39712, upgrade Ivanti Connect Secure to version 22.7R2.1 or 9.1R18.7 and Ivanti Policy Secure to version 22.7R1.1 or 9.1R18.7.
What are the affected versions in CVE-2024-39712?
Affected versions include Ivanti Connect Secure versions before 22.7R2.1 and 9.1R18.7, as well as Ivanti Policy Secure versions before 22.7R1.1 and 9.1R18.7.
Can CVE-2024-39712 be exploited remotely?
Yes, CVE-2024-39712 can be exploited remotely by an authenticated attacker with admin privileges.
What type of vulnerability is CVE-2024-39712?
CVE-2024-39712 is classified as an argument injection vulnerability allowing for potential remote code execution.