Ivanti Connect Secure
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*
- <= 22.7R2.5
A vulnerability allowing external control of file names has been identified in Ivanti Connect Secure versions prior to 22.7R2.4 and Ivanti Policy Secure versions prior to 22.7R1.3. This vulnerability allows remote authenticated attackers with admin privileges to write arbitrary files on the server.
Exploitation of this vulnerability could lead to unauthorized file writing, potentially allowing for further exploitation or disruption of the application.
Users can upgrade to Ivanti Connect Secure 22.7R2.6 or Ivanti Policy Secure 22.7R1.3. Instructions for downloading these versions are available on the Ivanti Download Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.