A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Connect_secure | Ivanti | 21.9-r1 (including) | 21.9-r1 (including) |
Connect_secure | Ivanti | 21.12-r1 (including) | 21.12-r1 (including) |
Connect_secure | Ivanti | 22.1-r1 (including) | 22.1-r1 (including) |
Connect_secure | Ivanti | 22.1-r6 (including) | 22.1-r6 (including) |
Connect_secure | Ivanti | 22.2-r1 (including) | 22.2-r1 (including) |
Connect_secure | Ivanti | 22.3-r1 (including) | 22.3-r1 (including) |
Connect_secure | Ivanti | 22.4-r1 (including) | 22.4-r1 (including) |