CVE-2024-10644
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
11/02/2025
Last modified:
11/02/2025
Description
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL