CVE-2023-41720: Ivanti Connect Secure
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.
Affected products
- Ivanti Connect Secure: version 22.1 only; version 22.2 only; version 22.3 only; version 22.4 only; version 22.5 only; version 22.6 only
Published 2023-12-14. Last modified 2026-06-17.