High severity7.8NVD Advisory· Published Dec 14, 2023· Updated Jun 17, 2026
CVE-2023-41720
CVE-2023-41720
Description
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.
Affected products
14cpe:2.3:a:ivanti:connect_secure:22.1:r1:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:ivanti:connect_secure:22.1:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.1:r6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.2:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.2:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.3:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.4:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.4:r2.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.5:r1.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.5:r2.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.6:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.6:r1:*:*:*:*:*:*
- (no CPE)range: <22.6R2
- (no CPE)range: 22.6.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.