Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Filtered by product Connect Secure
Total 130 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38657 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 4.9 MEDIUM
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
CVE-2024-38656 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 9.1 CRITICAL
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-38655 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 7.2 HIGH
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-38649 1 Ivanti 1 Connect Secure 2026-06-17 N/A 7.5 HIGH
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-37404 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 8.8 HIGH
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
CVE-2024-37401 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 7.5 HIGH
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-37400 1 Ivanti 1 Connect Secure 2026-06-17 N/A 7.5 HIGH
An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.
CVE-2024-37377 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 7.5 HIGH
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-22053 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 8.2 HIGH
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.
CVE-2024-22052 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 7.5 HIGH
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
CVE-2024-22024 1 Ivanti 3 Connect Secure, Policy Secure, Zero Trust Access Gateway 2026-06-17 N/A 8.3 HIGH
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
CVE-2024-22023 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 5.3 MEDIUM
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
CVE-2024-21894 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 9.8 CRITICAL
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code
CVE-2024-21888 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 8.8 HIGH
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.
CVE-2024-13843 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 6.0 MEDIUM
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
CVE-2024-13842 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 6.0 MEDIUM
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
CVE-2024-13830 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 6.1 MEDIUM
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
CVE-2024-12058 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 6.8 MEDIUM
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
CVE-2024-11634 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 9.1 CRITICAL
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
CVE-2024-11633 1 Ivanti 1 Connect Secure 2026-06-17 N/A 9.1 CRITICAL
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution