Lucene search

K
cveHackeroneCVE-2023-41720
HistoryDec 14, 2023 - 2:15 a.m.

CVE-2023-41720

2023-12-1402:15:12
hackerone
web.nvd.nist.gov
20
cve-2023-41720
ivanti connect secure
privilege escalation
vulnerability
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.1%

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.

Affected configurations

Nvd
Vulners
Node
ivanticonnect_secureMatch22.1r1
OR
ivanticonnect_secureMatch22.1r6
OR
ivanticonnect_secureMatch22.2-
OR
ivanticonnect_secureMatch22.2r1
OR
ivanticonnect_secureMatch22.3r1
OR
ivanticonnect_secureMatch22.4r1
OR
ivanticonnect_secureMatch22.4r2.1
OR
ivanticonnect_secureMatch22.4r2.2
OR
ivanticonnect_secureMatch22.5r1.1
OR
ivanticonnect_secureMatch22.5r2.1
Node
ivanticonnect_secureMatch22.6-
OR
ivanticonnect_secureMatch22.6r1
VendorProductVersionCPE
ivanticonnect_secure22.1cpe:2.3:a:ivanti:connect_secure:22.1:r1:*:*:*:*:*:*
ivanticonnect_secure22.1cpe:2.3:a:ivanti:connect_secure:22.1:r6:*:*:*:*:*:*
ivanticonnect_secure22.2cpe:2.3:a:ivanti:connect_secure:22.2:-:*:*:*:*:*:*
ivanticonnect_secure22.2cpe:2.3:a:ivanti:connect_secure:22.2:r1:*:*:*:*:*:*
ivanticonnect_secure22.3cpe:2.3:a:ivanti:connect_secure:22.3:r1:*:*:*:*:*:*
ivanticonnect_secure22.4cpe:2.3:a:ivanti:connect_secure:22.4:r1:*:*:*:*:*:*
ivanticonnect_secure22.4cpe:2.3:a:ivanti:connect_secure:22.4:r2.1:*:*:*:*:*:*
ivanticonnect_secure22.4cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*
ivanticonnect_secure22.5cpe:2.3:a:ivanti:connect_secure:22.5:r1.1:*:*:*:*:*:*
ivanticonnect_secure22.5cpe:2.3:a:ivanti:connect_secure:22.5:r2.1:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "vendor": "Ivanti",
    "product": "Connect Secure",
    "versions": [
      {
        "version": "22.6.1",
        "status": "affected",
        "lessThan": "22.6.1",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.1%

Related for CVE-2023-41720