CVE-2023-38551

HIGH

Ivanti Connect Secure <22.x - XSS

Title source: llm
STIX 2.1

Description

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.

Scores

CVSS v3 8.2
EPSS 0.0058
EPSS Percentile 69.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-93
Status published
Products (3)
Ivanti/Connect Secure 22.5R2.2
Ivanti/Connect Secure 22.7R2
Ivanti/Connect Secure 9.1R18.6
Published May 31, 2024
Tracked Since Feb 18, 2026