CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 03, 2024
- Published Date
- January 12, 2024
- Last Updated
- February 13, 2025
- Vendor
- Ivanti
- Product
- ICS, IPS
- Description
- A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
CVSS Scores
CVSS v3.0
Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-01-10 00:00:00 UTC |
Recent Mentions
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
Source: Tenable Blog • Published: 2025-04-23 04:05:00 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_21893.rb | 2025-04-29 11:01:13 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21887.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
ivanti_connect_secure_rce_cve_2023_46805
Type: metasploit • Created: Unknown
ivanti_connect_secure_rce_cve_2024_21893
Type: metasploit • Created: Unknown
tucommenceapousser/CVE-2024-21887
Type: github • Created: 2024-01-20 19:15:23 UTC • Stars: 2
Chocapikk/CVE-2024-21887
Type: github • Created: 2024-01-16 20:59:38 UTC • Stars: 55
oways/ivanti-CVE-2024-21887
Type: github • Created: 2024-01-14 09:25:56 UTC • Stars: 7