A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Connect_secure | Ivanti | 22.1-r1 (including) | 22.1-r1 (including) |
Connect_secure | Ivanti | 22.1-r6 (including) | 22.1-r6 (including) |
Connect_secure | Ivanti | 22.2 (including) | 22.2 (including) |
Connect_secure | Ivanti | 22.2-r1 (including) | 22.2-r1 (including) |
Connect_secure | Ivanti | 22.3-r1 (including) | 22.3-r1 (including) |
Connect_secure | Ivanti | 22.4-r1 (including) | 22.4-r1 (including) |
Connect_secure | Ivanti | 22.4-r2.1 (including) | 22.4-r2.1 (including) |
Connect_secure | Ivanti | 22.4-r2.2 (including) | 22.4-r2.2 (including) |
Connect_secure | Ivanti | 22.5-r1.1 (including) | 22.5-r1.1 (including) |
Connect_secure | Ivanti | 22.5-r2.1 (including) | 22.5-r2.1 (including) |