CVE-2024-37404
HIGHIvanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
Title source: metasploitDescription
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
by Richard Warren, Christophe De La Fuente · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb
Scores
CVSS v3
8.8
EPSS
0.8409
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
ivanti/connect_secure
9.1 r1 (45 CPE variants)
ivanti/connect_secure
22.7 (5 CPE variants)
Published
Oct 18, 2024
Tracked Since
Feb 18, 2026