---
id: CVE-2024-21887
title: >-
  A command injection vulnerability in web components of Ivanti Connect Secure
  (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)  allows an authenticated
  administrator to send specially crafted requests and execute arbitrary
  commands on the…
summary: >-
  A command injection vulnerability in web components of Ivanti Connect Secure
  (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)  allows an authenticated
  administrator to send specially crafted requests and execute arbitrary
  commands on the…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-77
vendor: ivanti
product: connect_secure
affected:
  - connect_secure = 9.0
  - connect_secure = 9.1
  - connect_secure = 22.1
  - connect_secure = 22.2
  - connect_secure = 22.3
  - connect_secure = 22.4
  - connect_secure = 22.5
  - connect_secure = 22.6
  - policy_secure = 9.0
  - policy_secure = 9.1
  - policy_secure = 22.1
  - policy_secure = 22.2
  - policy_secure = 22.3
  - policy_secure = 22.4
  - policy_secure = 22.5
  - policy_secure = 22.6
published: '2024-01-12'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-21887'
references:
  - url: >-
      http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html
    label: support@hackerone.com
  - url: >-
      https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
    label: support@hackerone.com
  - url: >-
      http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21887
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99999
epssPercentile: 1
kev: true
kevDateAdded: '2024-01-10'
kevDueDate: '2024-01-22'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-04T05:36:12.423Z'
exploits:
  github: 8
  githubRepos:
    - 'https://github.com/oways/ivanti-CVE-2024-21887'
    - 'https://github.com/duy-31/CVE-2023-46805_CVE-2024-21887'
    - 'https://github.com/Chocapikk/CVE-2024-21887'
  metasploit:
    - exploit/linux/http/ivanti_connect_secure_rce_cve_2023_46805
    - exploit/linux/http/ivanti_connect_secure_rce_cve_2024_21893
  nuclei:
    - CVE-2024-21887
  checkedAt: '2026-09-19T16:22:55.805Z'
exploitAvailable: true
---

## Overview

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)  allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

## Affected

- `connect_secure = 9.0`
- `connect_secure = 9.1`
- `connect_secure = 22.1`
- `connect_secure = 22.2`
- `connect_secure = 22.3`
- `connect_secure = 22.4`
- `connect_secure = 22.5`
- `connect_secure = 22.6`
- `policy_secure = 9.0`
- `policy_secure = 9.1`
- `policy_secure = 22.1`
- `policy_secure = 22.2`
- `policy_secure = 22.3`
- `policy_secure = 22.4`
- `policy_secure = 22.5`
- `policy_secure = 22.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
