CVE-2024-11005: Ivanti Connect Secure
High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected products
- Ivanti Connect Secure: before 9.1 (fixed in 9.1); after 9.1, before 22.7 (fixed in 22.7); version 22.7 only
- Ivanti Policy Secure: before 9.1 (fixed in 9.1); after 9.1, before 22.7 (fixed in 22.7); version 22.7 only
Published 2024-11-12. Last modified 2026-06-17.