Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
The flaw consists of insufficient input data validation leading to code injection (CWE-94) in Ivanti Connect Secure and Ivanti Policy Secure components. An authenticated attacker with administrator privileges can deliver a malicious payload that is executed on the server side in the application context. This results in the ability to execute code remotely (RCE) without requiring any user interaction.
An attacker can gain full control of the device by executing arbitrary code with system privileges — which can lead to data theft, installation of backdoors, or further movement within the internal network (lateral movement).
Ivanti Connect Secure should be updated to version 22.7R2.4 or later and Ivanti Policy Secure to version 22.7R1.3 or later. Details available in the vendor's statement: https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs
Ivanti Connect Secure in versions prior to 22.7R2.4 and Ivanti Policy Secure in versions prior to 22.7R1.3.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HIvanti Connect Secure
APPIvanti22.7< 22.7Ivanti Policy Secure
APPIvanti22.7< 22.7
Related vulnerabilities
Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE
Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA
Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator
Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE
Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia