OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-11006

 

OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-11006

Published: November 14, 2024


Vulnerability identifier: #VU100483
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11006
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote privileged user can send a specially crafted HTTP request and execute arbitrary OS commands on the target system.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2024-11006

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.2
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.3

External References

Related Security Bulletins