CVE-2024-38657

Published Feb 21, 2025

Last updated 7 days ago

Overview

Description
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
Source
support@hackerone.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.0

Type
Secondary
Base score
9.1
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-73

Social media

Hype score
Not currently trending
  1. Ivanti releases security updates for critical vulnerabilities, including CVE-2024-38657. Patch now to protect your systems. URL: https://t.co/F2pT9tBCqd (Note: The character count includes the URL.)

    @threatlight

    23 Feb 2025

    19 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-38657 ⚠️🔴 CRITICAL (9.1) 🏢 Ivanti - Connect Secure 🏗️ 22.7R2.4 🔗 https://t.co/kxEDS8mT9E #CyberCron #VulnAlert https://t.co/GkN38BQwF7

    @cybercronai

    21 Feb 2025

    106 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  3. CVE-2024-38657 External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attack… https://t.co/yMQJHXU6Y8

    @CVEnew

    21 Feb 2025

    430 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. [CVE-2024-38657: CRITICAL] Vulnerability in Ivanti Connect/Policy Secure versions before 22.7R2.4/22.7R1.3 allows remote authenticated attackers to write arbitrary files. #cybersecurity#cybersecurity,#vulnerability https://t.co/bIcvaZA04a https://t.co/mCS8TyWaNb

    @CveFindCom

    21 Feb 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Critical security flaws discovered in Ivanti products could allow attackers to execute arbitrary code remotely. The vulnerabilities (CVE-2024-38657, CVE-2025-22467, CVE-2024-10644, and CVE-2024-47908) impact Ivanti Connect Secure, Policy Secure, and Cloud Services… https://t.

    @achi_tech

    13 Feb 2025

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Ivanti Patches Critical Security Flaws! Ivanti issued urgent fixes for Connect Secure, Policy Secure, & Cloud Services to address critical RCE vulnerabilities (CVE-2025-22467, CVE-2024-38657) ⚠️ No exploits detected yet, but patch immediately! Meanwhile, SonicWall & Fo

    @dCypherIO

    12 Feb 2025

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-38657 impacts Ivanti Connect Secure and Policy Secure #CVE-2024-38657 #IvantiConnectSecure #IvantiPolicySecure https://t.co/1Up5qt9TAB

    @pravin_karthik

    12 Feb 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️ Ivanti ออกอัปเดตแก้ไขช่องโหว่ร้ายแรงบน Connect Secure (ICS) และ Policy Secure (IPS)! CVE-2024-38657 (CVSS 9.1) เสี่ยงโดนโจมตีจากระยะไกล 🔥 อัปเดตด่วน! อ่านรายละเอียดและวิธีอัปเดต: [https://t.co/sFbXsM7Sk4](https://t.co/sFbXsM7Sk4) #CyberSecurity #Ivanti #PatchNow

    @commencenow

    12 Feb 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Critical security flaws discovered in Ivanti products could allow attackers to execute arbitrary code remotely. The vulnerabilities (CVE-2024-38657, CVE-2025-22467, CVE-2024-10644, and CVE-2024-47908) impact Ivanti Connect Secure, Policy Secure, and Cloud Services… https://t.

    @TheHackersNews

    12 Feb 2025

    16353 Impressions

    62 Retweets

    128 Likes

    15 Bookmarks

    2 Replies

    3 Quotes