← Back to browse · API

CVE-2024-21888

Severity
HIGH
CVSS
8.8
EPSS
0.86806
Risk score
65.58
CISA KEV
No
PoC
No
Published
2024-01-31
Modified
2025-12-16
First seen
2026-08-07
Aliases
EUVD-2024-19499, GHSA-24GF-6M5F-H6PG
Products
Ivanti:ICS 22.6R2 ≤22.6R2, Ivanti:ICS 9.1R18 ≤9.1R18, Ivanti:IPS 22.6R1 ≤22.6R1, Ivanti:IPS 9.1R18 ≤9.1R18
Sources
euvd EUVD-2024-19499

Description

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

References