Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-21887
HistoryJan 12, 2024 - 5:15 p.m.

Command injection

2024-01-1217:15:00
PRIOn knowledge base
www.prio-n.com
11
command injection
ivanti connect secure
ivanti policy secure
web components
authenticated
arbitrary commands
vulnerability

8 High

AI Score

Confidence

Low

0.969 High

EPSS

Percentile

99.7%

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.