OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-11634

 

OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-11634

Published: December 11, 2024


Vulnerability identifier: #VU101677
CSH Severity: Low
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2024-11634
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper input validation. A remote user with admin privileges can pass specially crafted data to the device and execute arbitrary OS commands.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2024-11634

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.2
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.3

External References

Related Security Bulletins