CVE-2024-37404
65Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.1epss 71%
from disclosure to weapon0 days
Published on NVDOct 18
metasploitOct 8
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H