CVE-2023-38551

EUVD-2023-42350
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
hackeroneCNA
8.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ivanticonnect_secure
𝑥
≤ 22.7R2
CNA
ivanticonnect_secure
𝑥
≤ 22.5R2.2
CNA
ivanticonnect_secure
𝑥
≤ 9.1R18.6
CNA