A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.
References
Link | Resource |
---|---|
https://forums.ivanti.com/s/article/Security-patch-release-Ivanti-Connect-Secure-22-6R2-and-22-6R2-1?language=en_US | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2023-12-14 02:15
Updated : 2024-03-26 19:26
NVD link : CVE-2023-41719
Mitre link : CVE-2023-41719
CVE.ORG link : CVE-2023-41719
JSON object : View
Products Affected
ivanti
- connect_secure
CWE