SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-21887

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

KEVCRITICAL 9.1EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 January 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 10 January 2024 · due 22 January 2024 · used in ransomware campaigns
Weakness
CWE-77
Affected
ivanti/connect secure · ivanti/policy secure
Source
support@hackerone.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please apply mitigations per vendor instructions. For more information, please see: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2024-21887

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.