OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-11007

 

OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-11007

Published: November 14, 2024


Vulnerability identifier: #VU100482
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11007
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote privileged user can send a specially crafted HTTP request and execute arbitrary OS commands on the target system.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2024-11007

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.2
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.3

External References

Related Security Bulletins