Vulnerability Database

290,206

Total vulnerabilities in the database

CVE-2024-9420

A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9

and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution

  • Published: Nov 12, 2024
  • Updated: May 4, 2025
  • CVE: CVE-2024-9420
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CWEs:

Software From Fixed in
ivanti / connect_secure - 9.1
ivanti / connect_secure 9.1-r16.1 9.1-r16.1.x
ivanti / connect_secure 9.1-r16 9.1-r16.x
ivanti / connect_secure 9.1-r15 9.1-r15.x
ivanti / connect_secure 9.1-r15.2 9.1-r15.2.x
ivanti / connect_secure 9.1-r1 9.1-r1.x
ivanti / connect_secure 9.1-r2 9.1-r2.x
ivanti / connect_secure 9.1-r3 9.1-r3.x
ivanti / connect_secure 9.1-r4 9.1-r4.x
ivanti / connect_secure 9.1-r4.1 9.1-r4.1.x
ivanti / connect_secure 9.1-r4.3 9.1-r4.3.x
ivanti / connect_secure 9.1-r4.2 9.1-r4.2.x
ivanti / connect_secure 9.1-r5 9.1-r5.x
ivanti / connect_secure 9.1-r6 9.1-r6.x
ivanti / connect_secure 9.1-r7 9.1-r7.x
ivanti / connect_secure 9.1-r8 9.1-r8.x
ivanti / connect_secure 9.1-r8.1 9.1-r8.1.x
ivanti / connect_secure 9.1-r8.2 9.1-r8.2.x
ivanti / connect_secure 9.1 9.1.x
ivanti / connect_secure 9.1-r7.0 9.1-r7.0.x
ivanti / connect_secure 9.1-r8.4 9.1-r8.4.x
ivanti / connect_secure 9.1-r9 9.1-r9.x
ivanti / connect_secure 9.1-r9.1 9.1-r9.1.x
ivanti / connect_secure 9.1-r9.2 9.1-r9.2.x
ivanti / connect_secure 9.1-r10 9.1-r10.x
ivanti / connect_secure 9.1-r11 9.1-r11.x
ivanti / connect_secure 9.1-r11.3 9.1-r11.3.x
ivanti / connect_secure 9.1-r11.4 9.1-r11.4.x
ivanti / connect_secure 9.1-r11.5 9.1-r11.5.x
ivanti / connect_secure 9.1-r12 9.1-r12.x
ivanti / connect_secure 9.1-r12.1 9.1-r12.1.x
ivanti / connect_secure 9.1-r13 9.1-r13.x
ivanti / connect_secure 9.1-r13.1 9.1-r13.1.x
ivanti / connect_secure 9.1-r14 9.1-r14.x
ivanti / connect_secure 9.1-r14.4 9.1-r14.4.x
ivanti / connect_secure 9.1-r17 9.1-r17.x
ivanti / connect_secure 9.1-r17.1 9.1-r17.1.x
ivanti / connect_secure 9.1-r17.2 9.1-r17.2.x
ivanti / connect_secure 9.1-r18 9.1-r18.x
ivanti / connect_secure 9.1-r18.1 9.1-r18.1.x
ivanti / connect_secure 9.1-r18.2 9.1-r18.2.x
ivanti / connect_secure 9.1-r18.3 9.1-r18.3.x
ivanti / connect_secure 22.7 22.7.x
ivanti / connect_secure 22.7-r1 22.7-r1.x
ivanti / connect_secure 22.7-r1.1 22.7-r1.1.x
ivanti / connect_secure 22.7-r1.2 22.7-r1.2.x
ivanti / connect_secure 22.7-r1.3 22.7-r1.3.x
ivanti / connect_secure 22.7-r1.4 22.7-r1.4.x
ivanti / connect_secure 22.7-r1.5 22.7-r1.5.x
ivanti / connect_secure 22.7-r2 22.7-r2.x
ivanti / policy_secure - 22.7
ivanti / policy_secure 22.7 22.7.x
ivanti / policy_secure 22.7-r1 22.7-r1.x
ivanti / connect_secure 9.1-r1.0 9.1-r1.0.x
ivanti / connect_secure 9.1-r2.0 9.1-r2.0.x
ivanti / connect_secure 9.1-r3.0 9.1-r3.0.x
ivanti / connect_secure 9.1-r4.0 9.1-r4.0.x
ivanti / connect_secure 9.1-r5.0 9.1-r5.0.x
ivanti / connect_secure 9.1-r6.0 9.1-r6.0.x
ivanti / connect_secure 9.1-r8.0 9.1-r8.0.x
ivanti / connect_secure 9.1-r9.0 9.1-r9.0.x
ivanti / connect_secure 9.1-r10.0 9.1-r10.0.x
ivanti / connect_secure 9.1-r10.2 9.1-r10.2.x
ivanti / connect_secure 9.1-r11.0 9.1-r11.0.x
ivanti / connect_secure 9.1-r11.1 9.1-r11.1.x
ivanti / connect_secure 9.1-r12.2 9.1-r12.2.x
ivanti / connect_secure 9.1-r18.7 9.1-r18.7.x
ivanti / connect_secure 9.1-r18.8 9.1-r18.8.x
ivanti / connect_secure 21.9 22.7
ivanti / connect_secure 22.7-r2.1 22.7-r2.1.x
ivanti / connect_secure 22.7-r2.2 22.7-r2.2.x
ivanti / policy_secure 22.7-r1.1 22.7-r1.1.x