CVE-2023-46805, CVE-2024-21887: Auth bypass & command injection in Ivanti Connect Secure, 8.2 & 9.1 rating 🔥
Two 0-days in Ivanti product. Vulns allow to access restricted resources and execute arbitrary commands by sending special requests.
Search at Netlas.io:
👉🏻 Link: https://nt.ls/I0nJC
👉🏻 Dork: http.body:"welcome.cgi?p=logo"
Vendor's advisory: https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
Post #135
851

- 👾 5
- 👍 3
- 🔥 1