Feed/CVE-2024-21887
CVE-2024-21887CRITICALCVSS 9.1CISA KEV: Actively Exploited

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Published Jan 10, 2024·Updated Aug 4, 2026

NVD Description

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

Public Exploits & PoCs10 found

[POC] CVE-2023-46805 — CVE-2023-46805_CVE-2024-21887

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

7

[POC] CVE-2024-21887 — CVE-2024-21887

Remote Code Execution : Ivanti

1

[POC] CVE-2023-46805 — CVE-2023-46805_CVE-2024-21887_Scanner

Quick scanner for possible vulnerable Ivanti Connect Secure appliances by country using Shodan.

1

[POC] CVE-2023-46805 — CVE-2023-46805_CVE-2024-21887

The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.

1

[POC] CVE-2024-21887 — CVE-2024-21887

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

[POC] CVE-2024-21887 — ivanti_shell

CVE-2024-21887 Exploitation with Ngrok Reverse Shell

[POC] CVE-2024-21887 — ivanti-CVE-2024-21887

POC Checker for ivanti CVE-2024-21887 Command injcetion

[POC] CVE-2024-21887 — CVE-2024-21887

Ivanti Connect Secure & Ivanti Policy Secure allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance. (RCE Exploits)

[POC] CVE-2024-21893 — CVE-2024-21893-to-CVE-2024-21887

CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit

[POC] CVE-2024-21887 — CVE-2024-21887

exploit for ivanti

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free