Showing 14 vulnerabilities on this page for Connect Secure and Policy Secure

Signals CISA KEV Ransomware Nuclei
Ivanti vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Ivanti Connect Secure and Policy Secure Out-of-bounds Write

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code

CWE-703CWE-787Apr 4, 2024
CVSS9.8v3.1EPSS19%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ivanti Connect Secure and Policy Secure Improper Restriction of XML External Entity Reference

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

CWE-611Feb 13, 20241 related artifact
CVSS8.3v3.1EPSS94.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Ivanti Connect Secure Privilege Escalation

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

CWE-269Jan 31, 2024
CVSS8.8v3.1EPSS86.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CWE-77Jan 12, 20241 related artifact
CVSS9.1v3.1EPSS>99.9%PoCs14SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CWE-287Jan 12, 20241 related artifact
CVSS8.2v3.1EPSS>99.9%PoCs11SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CWE-669CWE-94May 27, 2021
CVSS7.2v3.1EPSS14.1%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ivanti Pulse Connect Secure Command Injection Vulnerability

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

CWE-77May 27, 2021
CVSS8.8v3.1EPSS22.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

CVSS8.8v3.1EPSS41.3%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CWE-287CWE-416Apr 23, 2021
CVSS10.0v3.1EPSS47.2%PoCs3SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Ivanti Pulse Connect Secure Code Execution Vulnerability

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

CWE-434Oct 28, 2020
CVSS7.2v3.1EPSS96.5%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Ivanti Pulse Connect Secure Code Execution Vulnerability

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

CWE-94Sep 29, 2020
CVSS7.2v3.1EPSS90.8%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Ivanti Connect Secure and Policy Secure Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

CWE-79May 8, 20191 related artifact
CVSS6.1v3.1EPSS4.06%PoCs0SignalsNot listed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CWE-22May 8, 20191 related artifact
CVSS10.0v3.1EPSS>99.9%PoCs16SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CWE-78Apr 26, 2019
CVSS7.2v3.1EPSS98.6%PoCs4SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX