Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-21888

 

Permissions, Privileges, and Access Controls in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2024-21888

Published: January 31, 2024 / Updated: April 5, 2024


Vulnerability identifier: #VU85961
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21888
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in the web interface. A remote user can bypass implemented security restrictions and gain administrative privileges.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2024-21888

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - addressed in versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins