CVE-2024-37404

HIGH

Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection

Title source: metasploit

Description

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Richard Warren, Christophe De La Fuente · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb

Scores

CVSS v3 8.8
EPSS 0.8409
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
ivanti/connect_secure 9.1 r1 (45 CPE variants)
ivanti/connect_secure 22.7 (5 CPE variants)
Published Oct 18, 2024
Tracked Since Feb 18, 2026