CVE-2024-38657

ENISA EUVD: EUVD-2025-4556 ↗
✓ Confirmed 0-Day
Triaged: March 20, 2026 3 articles Published: 2025-02-21

EPSS Score

Source: FIRST.org · 2026-05-23
0.58%
probability
This CVE has a 0.58% probability of being exploited in the next 30 days.
0% Top 69.0th percentile of all CVEs 100%

CVSS v3.0

Source: VulnerabilityLookup (CIRCL)
9.1
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.

Affected Products

Ivanti
Connect Secure
22.7R2.4
Ivanti
Policy Secure
22.7R1.3

Attack Intelligence

Signal Intelligence

Confidence
85%
EPSS 0.58%
CVSS v3.0 9.1
Mentions 3

CNA Information

CNA Assigner
hackerone

Analyst Note

CVE-2024-38657 is confirmed as a zero-day. Article [3] explicitly lists it as a critical flaw (CVSS 9.1) patched by Ivanti, and Article [1] documents active exploitation in the wild of Ivanti Connect Secure vulnerabilities with concurrent patch availability. The timing aligns with zero-day criteria: vulnerability was actively exploited before/with patch release.

Threat Actors 15

Mustang Panda
apt_group Information theft and espionage 🇨🇳 CN
Cobalt
apt_group Financial crime 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
[Unnamed group]
apt_group 🇨🇳 CN
Test Panda
apt_group 🇨🇳 CN
Operation Digital Eye
apt_group Information theft and espionage 🇨🇳 CN
Unnamed Actor
apt_group 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Impersonating Panda
apt_group 🇨🇳 CN
Big Panda
apt_group 🇨🇳 CN
Cyber Alliance
apt_group 🇺🇦 UA
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 20, 2026
Published DateFeb 21, 2025