CVE-2024-38657
ENISA EUVD: EUVD-2025-4556 ↗
✓ Confirmed 0-Day
Triaged: March 20, 2026
3 articles
Published: 2025-02-21
EPSS Score
Source: FIRST.org · 2026-05-23
0.58%
probability
This CVE has a 0.58% probability
of being exploited in the next 30 days.
0%
Top 69.0th percentile of all CVEs
100%
CVSS v3.0
Source: VulnerabilityLookup (CIRCL)9.1
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
VulnerabilityLookup (CNA)External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
Affected Products
Ivanti
Connect Secure
22.7R2.4
Ivanti
Policy Secure
22.7R1.3
Attack Intelligence
Signal Intelligence
Confidence
85%
EPSS
0.58%
CVSS v3.0
9.1
Mentions
3
CNA Information
CNA Assigner
hackerone
Analyst Note
CVE-2024-38657 is confirmed as a zero-day. Article [3] explicitly lists it as a critical flaw (CVSS 9.1) patched by Ivanti, and Article [1] documents active exploitation in the wild of Ivanti Connect Secure vulnerabilities with concurrent patch availability. The timing aligns with zero-day criteria: vulnerability was actively exploited before/with patch release.
Threat Actors 15
Mustang Panda
apt_group
Information theft and espionage
🇨🇳 CN
Cobalt
apt_group
Financial crime
🇷🇺 RU
Cron
apt_group
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
Harvester
apt_group
Information theft and espionage
Unknown
Hacking Team
apt_group
🇮🇹 IT
[Unnamed group]
apt_group
🇨🇳 CN
Test Panda
apt_group
🇨🇳 CN
Operation Digital Eye
apt_group
Information theft and espionage
🇨🇳 CN
Unnamed Actor
apt_group
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Impersonating Panda
apt_group
🇨🇳 CN
Big Panda
apt_group
🇨🇳 CN
Cyber Alliance
apt_group
🇺🇦 UA
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 20, 2026
Published DateFeb 21, 2025