CVE-2024-21887
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
⚠ KEVEPSS 100.0%
描述
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
如何修補 CVE-2024-21887
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2024-21887 正在被利用嗎?
是 — CVE-2024-21887 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。