Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
affected
22.7R2.1 (custom)
unaffected
Default status
affected
22.7R1.1 (custom)
unaffected
Description
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
22.7R2.1 (custom)
22.7R1.1 (custom)
References
forums.ivanti.com/...Secure-Access-Client-ISAC-Multiple-CVEs