CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 03, 2024
- Published Date
- January 12, 2024
- Last Updated
- February 13, 2025
- Vendor
- Ivanti
- Product
- ICS, IPS
- Description
- A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
- Tags
- Exploitation
- active
- Technical Impact
- total
CVSS Scores
CVSS v3.0
Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-01-10 00:00:00 UTC |
Recent Mentions
Written by: Casey Charrier, James Sadowski, Clement Lecigne, Vlad Stolyarov Executive Summary Google Threat Intelligence Group (GTIG) tracked 75...
Source: Google Threat Intelligence • Published: 2025-04-29 05:00:00 UTC
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
Source: Tenable Blog • Published: 2025-04-23 04:05:00 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_21893.rb | 2025-04-29 11:01:13 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21887.yaml | 2025-04-26 00:00:00 UTC |
Nessus | https://www.tenable.com/plugins/nessus/190367 | 2024-02-09 17:53:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
ivanti_connect_secure_rce_cve_2023_46805
Type: metasploit • Created: Unknown
ivanti_connect_secure_rce_cve_2024_21893
Type: metasploit • Created: Unknown
tucommenceapousser/CVE-2024-21887
Type: github • Created: 2024-01-20 19:15:23 UTC • Stars: 2
Chocapikk/CVE-2024-21887
Type: github • Created: 2024-01-16 20:59:38 UTC • Stars: 55
oways/ivanti-CVE-2024-21887
Type: github • Created: 2024-01-14 09:25:56 UTC • Stars: 7
Timeline
-
CVE ID Reserved
-
Added to KEVIntel
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Nessus
-
Detected by Nuclei
-
Detected by Metasploit