ZeroHour

CVE-2024-37404

large

Authenticated RCE via improper input validation in Ivanti Connect Secure admin portal

CVSS 3.1
8.8 high
EPSS
71%p99
Published
()
Modified
AI analysis

An improper input validation flaw in the admin web portal of Ivanti Connect Secure (SSL VPN gateway) and Ivanti Policy Secure (NAC appliance) allows a remote attacker who already holds valid credentials to trigger remote code execution on the appliance. The flaw is triggered by sending crafted input to the admin portal over the network; the attack path is low complexity and requires no user interaction. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 8.8). All Ivanti Connect Secure releases before 22.7R2.1 and 9.1R18.9, and all Ivanti Policy Secure releases before 22.7R1.1, are affected. The flaw is not yet on CISA's KEV list and no public proof-of-concept is known, but EPSS assigns a 71% probability of exploitation within 30 days (99th percentile), indicating a high likelihood of near-term exploitation.

What to do: Upgrade Ivanti Connect Secure to 22.7R2.1 (or 9.1R18.9 on the 9.1 line) and Ivanti Policy Secure to 22.7R1.1. Until patched, restrict admin portal access to trusted management networks and review appliance admin and audit logs for unexpected authenticated activity. Because exploitation requires valid credentials, also verify that privileged accounts on exposed appliances show no signs of compromise and enforce strong authentication for admin access.

Affected
Ivanti Connect Secureall versions before 22.7R2.1 and before 9.1R18.9
Ivanti Policy Secureall versions before 22.7R1.1
Estimated exposure
largetens of thousands of internet-exposed appliances (public scans counted roughly 20,000-30,000+ exposed Ivanti Connect Secure instances) — Internet-wide scans of Ivanti Connect Secure VPN/admin interfaces counted on the order of 20,000-30,000 exposed appliances during 2024, and the broader installed base including internally deployed Connect Secure and Policy Secure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

Vendors
ivanti
Products
connect secure, policy secure
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.