A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.
References
| Link | Resource |
|---|---|
| https://forums.ivanti.com/s/article/Security-patch-release-Ivanti-Connect-Secure-22-6R2-and-22-6R2-1?language=en_US | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-12-14 02:15
Updated : 2023-12-19 01:41
NVD link : CVE-2023-41719
Mitre link : CVE-2023-41719
JSON object : View
Products Affected
ivanti
- connect_secure
CWE
