CVE-2024-37404
largeAuthenticated RCE via improper input validation in Ivanti Connect Secure admin portal
An improper input validation flaw in the admin web portal of Ivanti Connect Secure (SSL VPN gateway) and Ivanti Policy Secure (NAC appliance) allows a remote attacker who already holds valid credentials to trigger remote code execution on the appliance. The flaw is triggered by sending crafted input to the admin portal over the network; the attack path is low complexity and requires no user interaction. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 8.8). All Ivanti Connect Secure releases before 22.7R2.1 and 9.1R18.9, and all Ivanti Policy Secure releases before 22.7R1.1, are affected. The flaw is not yet on CISA's KEV list and no public proof-of-concept is known, but EPSS assigns a 71% probability of exploitation within 30 days (99th percentile), indicating a high likelihood of near-term exploitation.
What to do: Upgrade Ivanti Connect Secure to 22.7R2.1 (or 9.1R18.9 on the 9.1 line) and Ivanti Policy Secure to 22.7R1.1. Until patched, restrict admin portal access to trusted management networks and review appliance admin and audit logs for unexpected authenticated activity. Because exploitation requires valid credentials, also verify that privileged accounts on exposed appliances show no signs of compromise and enforce strong authentication for admin access.
| Ivanti Connect Secure | all versions before 22.7R2.1 and before 9.1R18.9 |
| Ivanti Policy Secure | all versions before 22.7R1.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
- Vendors
- ivanti
- Products
- connect secure, policy secure
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.