CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-10644

CVSS 9.1v3.1pub. 2025-02-11upd. 2025-07-14

Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

🤖 AI Analysis
How it works

The flaw consists of insufficient input data validation leading to code injection (CWE-94) in Ivanti Connect Secure and Ivanti Policy Secure components. An authenticated attacker with administrator privileges can deliver a malicious payload that is executed on the server side in the application context. This results in the ability to execute code remotely (RCE) without requiring any user interaction.

Impact

An attacker can gain full control of the device by executing arbitrary code with system privileges — which can lead to data theft, installation of backdoors, or further movement within the internal network (lateral movement).

Mitigation & patch

Ivanti Connect Secure should be updated to version 22.7R2.4 or later and Ivanti Policy Secure to version 22.7R1.3 or later. Details available in the vendor's statement: https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs

Who is affected

Ivanti Connect Secure in versions prior to 22.7R2.4 and Ivanti Policy Secure in versions prior to 22.7R1.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ivanti Connect Secure

    APP
    Ivanti
    22.7< 22.7
  • Ivanti Policy Secure

    APP
    Ivanti
    22.7< 22.7
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-22457CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE

CVE-2025-0282CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA

CVE-2024-21887CRITICAL9.1⚠ KEVPL ✓same product

Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator

CVE-2021-22893CRITICAL10.0⚠ KEVPL ✓same product

Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE

CVE-2019-11510CRITICAL10.0⚠ KEVPL ✓same product

Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia