CVE-2023-41720
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/12/2023
Last modified:
19/12/2023
Description
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ivanti:connect_secure:9.1:r15:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:9.1:r16:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:9.1:r16.1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:21.9:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:21.12:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.1:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.1:r6:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.2:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.3:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.4:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.4:r2.1:*:*:*:*:*:* | ||
| cpe:2.3:a:ivanti:connect_secure:22.5:r2.1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



