Ivanti Connect Secure
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*
- <= 22.7R2.5
A code injection vulnerability has been identified in Ivanti Connect Secure versions prior to 22.7R2.4 and Ivanti Policy Secure versions prior to 22.7R1.3. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on the affected systems.
Exploitation of this vulnerability leads to unauthorized remote code execution on the affected system.
Users can upgrade to Ivanti Connect Secure version 22.7R2.6 or Ivanti Policy Secure version 22.7R1.3. These versions are available through the Ivanti Download Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.