Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-21888
Published: January 31, 2024 / Updated: April 5, 2024
Vulnerability identifier: #VU85961
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21888
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in the web interface. A remote user can bypass implemented security restrictions and gain administrative privileges.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2024-21888
Install updates from vendor's website.
Ivanti Policy Secure (formerly Pulse Policy Secure) - addressed in versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1