CVE Vulnerabilities

CVE-2024-47906

Privilege Defined With Unsafe Actions

Published: Nov 12, 2024 | Modified: Jan 17, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
Connect_secureIvanti*9.1 (excluding)
Connect_secureIvanti9.1 (excluding)22.7 (excluding)
Connect_secureIvanti22.7 (including)22.7 (including)
Connect_secureIvanti22.7-r1 (including)22.7-r1 (including)
Connect_secureIvanti22.7-r1.1 (including)22.7-r1.1 (including)
Connect_secureIvanti22.7-r1.2 (including)22.7-r1.2 (including)
Connect_secureIvanti22.7-r1.3 (including)22.7-r1.3 (including)
Connect_secureIvanti22.7-r1.4 (including)22.7-r1.4 (including)
Connect_secureIvanti22.7-r1.5 (including)22.7-r1.5 (including)
Connect_secureIvanti22.7-r2 (including)22.7-r2 (including)
Connect_secureIvanti22.7-r2.1 (including)22.7-r2.1 (including)
Connect_secureIvanti22.7-r2.2 (including)22.7-r2.2 (including)
Policy_secureIvanti*9.1 (excluding)
Policy_secureIvanti9.1 (excluding)22.7 (excluding)
Policy_secureIvanti22.7-r1 (including)22.7-r1 (including)
Policy_secureIvanti22.7-r1.1 (including)22.7-r1.1 (including)

Potential Mitigations

References