Main
Vulnerability Database
Exploits
ID:9658 - Exploit for Permissions, Privileges, and Access Controls in Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure (formerly Pulse Policy Secure) - CVE-2024-21888
ID:9658 - Exploit for Permissions, Privileges, and Access Controls in Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure (formerly Pulse Policy Secure) - CVE-2024-21888
Published: April 5, 2024
Vulnerability identifier: #VU85961
Vulnerability risk: Medium
CVE-ID: CVE-2024-21888
CWE-ID: CWE-264
Exploitation vector: Remote access
Vulnerable software:
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in the web interface. A remote user can bypass implemented security restrictions and gain administrative privileges.
Remediation
Install updates from vendor's website.