Ivanti Command Injection (CVE-2023-46805; CVE-2024-21887)

Related Vulnerabilities: CVE-2023-46805   CVE-2024-21887  

Check Point Reference: CPAI-2024-0013 Date Published: 11 Jan 2024 Severity: High Last Updated: Thursday 11 January, 2024 Source: Industry Reference:CVE-2023-46805
CVE-2024-21887
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Ivanti Connect Secure 9.x
Ivanti Connect Secure 22.x
Ivanti Policy Secure Vulnerability Description A command injection vulnerability exists in Ivanti. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands on the affected system.