← Vulnerability feed

Vulnerability record · CVE-2024-37404 · published 18 October 2024

CVE-2024-37404: Ivanti Connect Secure admin portal input validation flaw enables RCE

Ivanti · Connect Secure

Ivanti Connect Secure and Policy Secure contain an improper input validation flaw in the admin portal. A remote authenticated attacker can exploit it to achieve remote code execution on the appliance. Because these are edge security gateways, successful exploitation can expose the internal network.

8.8 CVSS 3.1 High EPSS 71% · top 0.6%
8.8CVSS 3.1 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution on an edge security appliance with a CVSS of 8.8 and very high EPSS, though it requires authenticated admin access.

What it is

Ivanti Connect Secure and Policy Secure contain an improper input validation flaw in the admin portal. A remote authenticated attacker can exploit it to achieve remote code execution on the appliance. Because these are edge security gateways, successful exploitation can expose the internal network.

Impact

An attacker with valid admin-portal credentials gains remote code execution on the appliance, allowing them to run commands, access secrets and pivot into the protected network.

Attack surface

Reached over the network through the admin portal (AV:N, AC:L, PR:L, UI:N). Authentication is required; no user interaction is needed.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.70955 (99.37th percentile), indicating a high predicted likelihood of exploitation.

What to do

  • Apply the vendor patch: upgrade Connect Secure to 22.7R2.1 or 9.1R18.9, and Policy Secure to 22.7R1.1 or later.
  • Restrict admin portal access to trusted management networks and disable internet-facing admin interfaces.
  • Enforce strong unique credentials and MFA for all admin accounts; audit for stale or shared accounts.
  • Monitor and rotate any credentials or secrets stored on or accessible from the appliance.
  • Review Ivanti advisory guidance for additional hardening and compromise checks.

Detection

  • Monitor admin portal logs for unexpected command execution, process spawning or web shell activity.
  • Alert on anomalous admin logins, especially from new source IPs or outside maintenance windows.
  • Hunt for outbound connections from the appliance to unusual destinations that could indicate post-exploitation.
  • Check for unexpected files, scheduled tasks or configuration changes on the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37404 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-37404), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.