Evidence dossier

CVE-2024-21887

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send…

Exploited in the wild (CISA KEV since Jan 10, 2024). NVD reports CVSS 3.1 9.1. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.

82.797.4Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

State
PUBLISHED
Published
Jan 12, 2024
Updated
Aug 4, 2026
Evidence coverage
85%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
    Original evidence ↗
  2. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 100% probability · 100th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999990000000; percentile 0.999990000000
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  5. Source dateSource date omittedFirst observed by CASCA
    hackerone

    Record text: A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    Inspect raw assertion
    Field
    container
    Value
    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jan 10, 2024 · first observed Jul 19, 2026

Exploit likelihood100.00%

FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026

SeverityCVSS 9.1

NVD · CVSS 3.1 · first observed Aug 4, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

100% probability · 100th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999990000000; percentile 0.999990000000
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
hackeroneOriginal assertion
Record text

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

Inspect raw assertion
Field
container
Value
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
81Underlying assertions
2Canonical products
81Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

4 scope groups

hackerone · source assertedIvantiICSDirect source scope
Affected: 9.1R18 through 9.1R18 (custom comparison)Affected: 22.6R2 through 22.6R2 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.1R18", "versionType": "custom", "lessThanOrEqual": "9.1R18"}, {"status": "affected", "version": "22.6R2", "versionType": "custom", "lessThanOrEqual": "22.6R2"}]
hackerone · source assertedIvantiIPSDirect source scope
Affected: 9.1R18 through 9.1R18 (custom comparison)Affected: 22.6R1 through 22.6R1 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.1R18", "versionType": "custom", "lessThanOrEqual": "9.1R18"}, {"status": "affected", "version": "22.6R1", "versionType": "custom", "lessThanOrEqual": "22.6R1"}]
NVD CPE · APPLICATIONivanticonnect_secureVulnerable target · 44 assertions
Version 22.1; Version 22.2; Version 22.3; Version 22.4; Version 22.5; Version 22.6; Version 9.0; Version 9.1Canonical identity product-0675def37879dcf14a27022586db7f5234f5d2c3f293e3a70a47a5da19da3b1bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:ivanti:connect_secure:22.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6564fe9e-7d96-4226-8378-dac25525cdd1
  2. cpe:2.3:a:ivanti:connect_secure:9.1:r14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c132ba26-bca0-43e6-9511-34acffa136a9
  3. cpe:2.3:a:ivanti:connect_secure:9.1:r13.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3027a9ce-849e-4cae-a1c4-170deaf4fe86
  4. cpe:2.3:a:ivanti:connect_secure:9.1:r17.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e238ab9f-99c1-4f0d-b442-d390065d35d1
  5. cpe:2.3:a:ivanti:connect_secure:9.1:r11.4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f2a7f5c-1d78-4d19-b8ed-5822fdf5da63
  6. cpe:2.3:a:ivanti:connect_secure:22.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80c56782-273a-4151-be81-13feefe46a6a
  7. cpe:2.3:a:ivanti:connect_secure:22.4:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d3df17ac-ec26-4b76-8989-b7880c9ef73e
  8. cpe:2.3:a:ivanti:connect_secure:9.1:r9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16daa769-8f0d-4c54-a8d9-9902995605b0
  9. cpe:2.3:a:ivanti:connect_secure:9.1:r16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44c26423-8621-4f6d-a45b-0a6b6e873ab6
  10. cpe:2.3:a:ivanti:connect_secure:22.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c383863-1e90-4b72-a500-4326782bc92f
  11. cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4b21c181-dc49-4ebd-9932-dbb337151ff7
  12. cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3de32a0c-8944-4f51-a286-266055ca4b2f
  13. cpe:2.3:a:ivanti:connect_secure:9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    beaa1f3f-fc78-43c1-814a-19e94ac4a844
  14. cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db7a6d62-6576-4713-9bf4-11068a72e8b7
  15. cpe:2.3:a:ivanti:connect_secure:9.1:r12.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bbc724e8-195b-4cb4-ac2a-63e184aed4f6
  16. cpe:2.3:a:ivanti:connect_secure:22.2:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bcbf6dd0-2826-4e61-8fb6-db489ebf8981
  17. cpe:2.3:a:ivanti:connect_secure:9.1:r13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    65435a96-ef7a-439a-aa6c-cb7eaef0a963
  18. cpe:2.3:a:ivanti:connect_secure:22.6:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab9a5868-34fb-446e-817f-6701cc5de923
  19. cpe:2.3:a:ivanti:connect_secure:9.1:r8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9fa0b20d-3fa1-42ae-bdc5-93d8a182927c
  20. cpe:2.3:a:ivanti:connect_secure:9.1:r11.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    366ef5b8-0233-49b8-806a-e54f60410ade
  21. cpe:2.3:a:ivanti:connect_secure:9.1:r11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d5f47ba-de6d-443d-95c3-a45f80edc71e
  22. cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0349a0cc-a372-4e51-899e-d7ba67876f4b
  23. cpe:2.3:a:ivanti:connect_secure:9.1:r9.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2c10c89-1dbc-4e91-bd28-d5097b589ca9
  24. cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3ccc2d7b-f835-45ec-a316-2f0c5f2cf565
  25. cpe:2.3:a:ivanti:connect_secure:22.3:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    415219d0-2d9a-4617-abb7-6ff918421bee
  26. cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad812596-c77c-4129-982f-c22a25b52126
  27. cpe:2.3:a:ivanti:connect_secure:9.1:r15.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7dbcd6b-b7aa-4ab0-852f-563a2ec85db4
  28. cpe:2.3:a:ivanti:connect_secure:22.6:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5456f61d-1fd1-4da6-afa3-4073889ad22a
  29. cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    93d1a098-bd77-4a7b-9070-a764fb435981
  30. cpe:2.3:a:ivanti:connect_secure:22.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    361faa47-52ff-4b36-96b0-9c178a4e031b
  31. cpe:2.3:a:ivanti:connect_secure:9.1:r10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a3a93fe-41bf-43f2-9efc-89656182329f
  32. cpe:2.3:a:ivanti:connect_secure:9.1:r15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ce228fbd-5ad1-4bc6-af63-5248e671b04f
  33. cpe:2.3:a:ivanti:connect_secure:9.1:r8.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bffa0b02-7f6d-4434-b1e7-eb8520fd68a0
  34. cpe:2.3:a:ivanti:connect_secure:9.1:r12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    32e0b425-a9ba-4d00-84a9-46268072d696
  35. cpe:2.3:a:ivanti:connect_secure:9.1:r17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db6cea16-f422-48f1-9473-3931b1bfa63f
  36. cpe:2.3:a:ivanti:connect_secure:9.1:r18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28fde909-711c-41ec-8ba6-ac4de05ea27e
  37. cpe:2.3:a:ivanti:connect_secure:22.4:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9f55e7b-7b38-4aec-a015-d8cb9de5e72c
  38. cpe:2.3:a:ivanti:connect_secure:22.5:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    001e117b-e8ee-4c20-aebf-34ff5eb5051e
  39. cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4fefc4b1-7350-46f9-80c1-42f5ae06142f
  40. cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d5355372-03ea-46d7-9104-a2785c29b664
  41. cpe:2.3:a:ivanti:connect_secure:9.1:r8.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfe8fa87-9622-4d5b-99c7-d8ee230c0aa9
  42. cpe:2.3:a:ivanti:connect_secure:9.1:r16.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bc391eb5-c457-459c-8eaa-ea0043487c0b
  43. cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    843bc1b9-50cc-4f8f-a454-a0cec6e92290
  44. cpe:2.3:a:ivanti:connect_secure:9.1:r11.5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ddda231-2a5e-4c70-8620-535c7f9027a4
NVD CPE · APPLICATIONivantipolicy_secureVulnerable target · 37 assertions
Version 22.1; Version 22.2; Version 22.3; Version 22.4; Version 22.5; Version 22.6; Version 9.0; Version 9.1Canonical identity product-66735516e7e23282d6cbb1b21ef896b9b737013272849d8db9227bbeb2d5728aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:ivanti:policy_secure:9.1:r7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac3863bc-3b9a-402b-a74a-149cdf717ec6
  2. cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6d37a6e4-d58e-444d-af6a-15461f38e81a
  3. cpe:2.3:a:ivanti:policy_secure:9.1:r10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bf767f07-2e9f-4099-829d-2f70e85d8a35
  4. cpe:2.3:a:ivanti:policy_secure:22.5:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 78
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb4b1ed6-38ad-44f8-9b77-2d6924e8a20e
  5. cpe:2.3:a:ivanti:policy_secure:9.1:r13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d50c5526-f791-4c76-b5c0-da2e1281c9e2
  6. cpe:2.3:a:ivanti:policy_secure:9.1:r14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a53c031-e7a5-47b6-ba4a-dd28432e743f
  7. cpe:2.3:a:ivanti:policy_secure:22.5:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 79
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28a9318a-0d4d-4ef1-998b-4a82a1ab63f0
  8. cpe:2.3:a:ivanti:policy_secure:22.4:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 77
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3eb8380f-d229-4af0-b27c-47760f843e48
  9. cpe:2.3:a:ivanti:policy_secure:22.6:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 80
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    56c7542d-3520-4e4d-936c-5295068c4cd7
  10. cpe:2.3:a:ivanti:policy_secure:9.1:r18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    811c7e7e-89ab-47df-bacd-ed478df756bc
  11. cpe:2.3:a:ivanti:policy_secure:9.1:r12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fe5c4abc-2beb-4741-95b3-303903369818
  12. cpe:2.3:a:ivanti:policy_secure:22.4:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 76
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    14b481e8-d887-408f-b892-d2939cd037ab
  13. cpe:2.3:a:ivanti:policy_secure:9.1:r16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b90687f3-a5c1-4706-ad66-d78ee512e4c9
  14. cpe:2.3:a:ivanti:policy_secure:9.1:r4.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d55ab5f0-132f-4c40-bf4f-684e139b774b
  15. cpe:2.3:a:ivanti:policy_secure:22.2:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 72
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1536db45-9a42-4549-a10e-fdbb6693df17
  16. cpe:2.3:a:ivanti:policy_secure:22.3:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 74
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8bbc1e81-0a2a-4166-bfa6-2b866b4f8ae4
  17. cpe:2.3:a:ivanti:policy_secure:9.1:r5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6be937d2-8bee-4e64-8738-f550ead00f50
  18. cpe:2.3:a:ivanti:policy_secure:9.1:r17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d10a3f2d-6a62-4a48-93fb-274527c821d2
  19. cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a07b66e0-a679-4912-8cb1-cd134713edc7
  20. cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9a5ba3e-d6b3-453d-8ddf-ff16859fd0f8
  21. cpe:2.3:a:ivanti:policy_secure:9.1:r15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4bee355b-1c2d-4beb-8922-eaeaa5a1fae8
  22. cpe:2.3:a:ivanti:policy_secure:9.1:r11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b994e22b-8fa5-4510-82f6-7820bda7c307
  23. cpe:2.3:a:ivanti:policy_secure:9.1:r8.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cce2e1c0-680f-4eff-ace6-a1dafa209d24
  24. cpe:2.3:a:ivanti:policy_secure:22.3:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 73
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51ff66c9-9415-4ead-8f19-d5e067336885
  25. cpe:2.3:a:ivanti:policy_secure:22.4:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 75
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d73729eb-c679-4ced-9f36-212b0581ec22
  26. cpe:2.3:a:ivanti:policy_secure:9.1:r13.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2cb8240e-7683-4c39-9654-4f8d1f682288
  27. cpe:2.3:a:ivanti:policy_secure:9.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9c753520-1bc6-4980-afc9-4c2fddf2fd18
  28. cpe:2.3:a:ivanti:policy_secure:9.1:r8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e3c09d51-fda0-4d07-87d8-f527c8cbdafb
  29. cpe:2.3:a:ivanti:policy_secure:9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dd00e2ec-b772-4fe8-8cc5-829be45be878
  30. cpe:2.3:a:ivanti:policy_secure:9.1:r3.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    38a0d7cf-7d55-4933-ae8c-36006d6779e1
  31. cpe:2.3:a:ivanti:policy_secure:22.2:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 71
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    34c118fb-7ae0-466c-822a-348a2f6016ac
  32. cpe:2.3:a:ivanti:policy_secure:22.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    925dccba-9382-4a39-84b8-4deafd2bc802
  33. cpe:2.3:a:ivanti:policy_secure:9.1:r8.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7ed1686b-2d80-4ecf-9f7a-aea989e17c84
  34. cpe:2.3:a:ivanti:policy_secure:22.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a385f38b-0b03-4b69-b7a1-952f5bae727c
  35. cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fc2b9da0-e32b-4125-9986-f0d3814c66e9
  36. cpe:2.3:a:ivanti:policy_secure:9.1:r9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    092da2a3-5cef-433f-8e5b-4850e4095cc4
  37. cpe:2.3:a:ivanti:policy_secure:9.1:r4.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bafda618-d15d-401d-ac68-0020259fec57

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.1
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
9.1
support@hackerone.comCVSS 3.0 · role Secondary · priority eligiblevalid_matchCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
9.1
hackeroneCVSS 3.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.