CVE-2024-37404
CVE-2024-37404 is a critical remote code execution vulnerability affecting Ivanti Connect Secure and Ivanti Policy Secure. Due to improper input validation in the admin portal, a remote, authenticated attacker could exploit this flaw to execute arbitrary code on the system. The vulnerability impacts versions before 22.7R2.1 and 9.1R18.9 for Connect Secure, and before 22.7R1.1 for Policy Secure. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a moderate risk, although not immediately critical, should still be addressed promptly. Exploitation could lead to complete system compromise and data breach. This vulnerability is especially significant for organizations relying on Ivanti for secure connectivity and policy enforcement. Although not critical, the fact that it is 'In The Wild' suggests potential for increased exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.