VYPR

Policy Secure

by Ivanti

CVEs (59)

  • CVE-2024-21887CriKEVJan 12, 2024
    risk 0.88cvss 9.1epss 1.00

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

  • CVE-2025-22457CriKEVApr 3, 2025
    risk 0.87cvss 9.0epss 1.00

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2025-0282CriKEVJan 8, 2025
    risk 0.87cvss 9.0epss 1.00

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2024-21893HigKEVJan 31, 2024
    risk 0.82cvss 8.2epss 1.00

    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

  • CVE-2023-46805HigKEVJan 12, 2024
    risk 0.82cvss 8.2epss 1.00

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

  • CVE-2024-37404HigOct 18, 2024
    risk 0.66cvss 8.8epss 0.67

    Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

  • CVE-2024-21894CriApr 4, 2024
    risk 0.65cvss 9.8epss 0.19

    A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may…

  • CVE-2024-21888HigJan 31, 2024
    risk 0.64cvss 8.8epss 0.87

    A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

  • CVE-2024-22024HigFeb 13, 2024
    risk 0.62cvss 8.3epss 0.95

    An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

  • CVE-2024-10644CriFeb 11, 2025
    risk 0.59cvss 9.1epss 0.02

    Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11634CriDec 10, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)

  • CVE-2024-39712CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-39711CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-39710CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-38656CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11006CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11005CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11007CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-9420HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.01

    A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution

  • CVE-2024-22053HigApr 4, 2024
    risk 0.54cvss 8.2epss 0.04

    A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read…

Page 1 of 3

VYPR — Vulnerability Intelligence