CVE-2024-38657

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
Configurations

No configuration.

History

21 Feb 2025, 16:15

Type Values Removed Values Added
CWE CWE-73

21 Feb 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 02:15

Updated : 2025-02-21 16:15


NVD link : CVE-2024-38657

Mitre link : CVE-2024-38657

CVE.ORG link : CVE-2024-38657


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path