External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
https://www.securityweek.com/ivanti-fortinet-patch-remote-code-execution-vulnerabilities/
https://thehackernews.com/2025/02/ivanti-patches-critical-flaws-in.html