Ivanti Connect Secure
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*
- <= 22.7R2.5
A vulnerability exists in Ivanti Connect Secure (ICS) versions prior to 22.7R2.3 and Ivanti Policy Secure (IPS) versions prior to 22.7R1.3. This vulnerability is due to a hardcoded key that enables a local authenticated attacker with admin privileges to read sensitive data.
Exploitation of this vulnerability allows for unauthorized access to sensitive data.
Users can upgrade to Ivanti Connect Secure version 22.7R2.6 or Ivanti Policy Secure version 22.7R1.3. These versions are available on the Ivanti Download Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.