Executive brief
A command injection vulnerability in the web components of Ivanti Connect Secure and Policy Secure allows an authenticated administrator to execute arbitrary commands via specially crafted requests. This vulnerability is known to be exploited in the wild, often in conjunction with CVE-2023-46805 to bypass authentication.
Affected products
- Ivanti Connect Secure 9.x, 22.x
- Ivanti Policy Secure 9.x, 22.x
Timeline
- 2024-01-10: disclosed
- 2024-01-10: kev added: Added to CISA KEV catalog
- 2024-01-10: exploited: Reported as exploited in the wild at time of publication