EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-10TLP:CLEAR
vulnerabilitycritical
Ivanti Connect Secure & Policy Secure Command Injection
EXECUTIVE INTELLIGENCE SUMMARY
Command injection in Ivanti web component allowing authenticated administrators (or unauthenticated attackers when chained with CVE-2023-46805) to execute arbitrary commands.
Chained with an authentication bypass in the `/api/v1/totp/user-backup-code` endpoint, attackers send malicious JSON payloads to the `/api/v1/license/keys-status/` URI, appending bash shell injection parameters that execute with root privileges on the appliance.
TECHNICAL EXPLOITATION MATRIX
CVSS v4.0 SCORE
9.1 / 10.0
CRITICAL BASE SEVERITY
EPSS EXPLOIT PROBABILITY
97.4%
PERCENTILE 98.4
EXPLOITED IN THE WILD
CONFIRMED
CISA KEV CATALOG
AFFECTED SOFTWARE BUILDS
Ivanti Connect Secure (Ivanti)
AFFECTED: 9.x, 22.x
FIXED IN: 22.6R2.1
RECOMMENDED REMEDIATION & MITIGATIONS
- [1]Apply Ivanti XML workaround mitigating REST API routing.
- [2]Run External Integrity Checker Tool (ICT) for indicators of persistent webshells.
SOURCE CITATIONS & ATTESTATIONS (1)
CISA Emergency Directive 24-01CISA
Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities
TELEMETRY CARDID: cve-2024-21887
ENTITY TYPE
vulnerability
INDEXED TAGS
#vpn_gateway#edge_device#ivanti#cisa_kev#command_injection
CONNECTED ENTITIES (2)VIEW IN GRAPH →