Ivanti Connect Secure 22.7 R2.1

CPE Details

Ivanti Connect Secure 22.7 R2.1
22.7
2024-12-24
17h26 +00:00
2024-12-24
17h26 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:*

Informations

Vendor

ivanti

Product

connect_secure

Version

22.7

Update

r2.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-13843 2025-02-11 15h26 +00:00 Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
6
Medium
CVE-2024-13842 2025-02-11 15h25 +00:00 A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
6
Medium
CVE-2024-13830 2025-02-11 15h22 +00:00 Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
6.1
Medium
CVE-2025-22467 2025-02-11 15h20 +00:00 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
9.9
Critical
CVE-2025-0283 2025-01-08 22h15 +00:00 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
7
High
CVE-2025-0282 2025-01-08 22h15 +00:00 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
9
Critical
CVE-2024-11634 2024-12-10 18h48 +00:00 Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
9.1
Critical
CVE-2024-11633 2024-12-10 18h47 +00:00 Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
9.1
Critical
CVE-2024-9844 2024-12-10 18h46 +00:00 Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
8.8
High
CVE-2024-47909 2024-11-12 16h02 +00:00 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
4.9
Medium
CVE-2024-47907 2024-11-12 16h00 +00:00 A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-47906 2024-11-12 15h59 +00:00 Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.
7.8
High
CVE-2024-9420 2024-11-12 15h57 +00:00 A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
8.8
High
CVE-2024-47905 2024-11-12 15h56 +00:00 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
4.9
Medium