ZeroHour
The Recordpublished ()ingested

Two new Ivanti bugs discovered as CISA warns of hackers bypassing mitigations

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21887
+1 in the same advisory: …46805
Command Injection RCE in Ivanti Connect Secure and Policy Secure

Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available.

Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories.

9.1
group max
100% KEV ransomware PoC
  • Ivanti Connect Secure (ICS, formerly Pulse Connect Secure)
  • Ivanti Policy Secure
largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher)
CVE-2024-21888
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privile

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

NVD description · AI analysis pending
8.887%
  • ivanti connect secure
  • ivanti policy secure
CVE-2024-21893
SSRF in Ivanti Connect Secure, Policy Secure, and Neurons SAML Component

CVE-2024-21893 is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (formerly Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons. A remote attacker can trigger the flaw with crafted unauthenticated requests to the SAML component, causing the appliance to make requests to otherwise restricted resources. Successful exploitation allows the attacker to access certain restricted resources without any credentials, and CISA notes the flaw has been used in ransomware operations. Any organization running an affected Ivanti Connect Secure, Policy Secure, or Neurons deployment is exposed, particularly where the appliance is reachable from the internet. The vulnerability is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-31, carries an EPSS probability of 100%, and no public proof-of-concept is known.

Do: Apply Ivanti's released patches or the vendor-issued mitigations immediately per vendor instructions, or discontinue use of the product if mitigations are unavailable, as required by CISA. Because ransomware use is documented, review SAML-related logs and appliance audit trails for signs of exploitation and follow-on compromise, and check for indicators of post-exploitation activity. Monitor Ivanti advisories for patched version numbers and updated mitigation guidance, since specific fixed versions are not yet specified in the available data.

8.2100% KEV ransomware
  • Ivanti Connect Secure (formerly Pulse Connect Secure)
  • Ivanti Policy Secure
  • Ivanti Neurons
largetens of thousands of internet-exposed appliances (with total user counts likely in the hundreds of thousands)
Full article698 words · extracted from therecord.media · click to collapse

IT company Ivanti said this week that it discovered two new vulnerabilities affecting its products while investigating bugs discovered earlier in the month.

The issues affect Ivanti’s Policy Secure and Ivanti Connect Secure VPN products, which are used widely across the U.S. government and other industries. The two vulnerabilities — referred to as CVE-2024-21888 and CVE-2024-21893 — affect all supported versions.

The company said “a small number of customers” have been impacted by CVE-2024-21893, which allows an attacker "to access certain restricted resources without authentication.” It has no evidence of any customers being affected by CVE-2024-21888, which allows a hacker to elevate their privileges to that of an administrator, providing wider access to a victim's network.

“Upon learning of these vulnerabilities, we immediately mobilized resources and the patch is available now… It is critical that you immediately take action to ensure you are fully protected,” the company said.

Changing patch schedule

The company’s advisory came one day after concerns were raised by the U.S. government and security experts about the mitigations publicized for two other Ivanti bugs — CVE-2023-46805 and CVE-2024-21887. Experts have warned for weeks that hackers are exploiting the bugs because they allow attackers “to move laterally, perform data exfiltration, and establish persistent system access, resulting in full compromise of target information systems.”

The bugs were of such concern to cybersecurity officials within the U.S. government that they took the extraordinary step of mandating that all federal civilian agencies patch them immediately.

In a press briefing two weeks ago, a senior CISA official said the agency has “observed some initial targeting of federal agencies” and is investigating each situation. The official explained that there are “around 15 agencies that were using these products” but declined to confirm if any dealt with compromises.

The agencies using the tools cover “a wide spectrum … across the breadth of the federal mission,” the official said.

On Tuesday, CISA warned that hackers are still leveraging the vulnerabilities to steal credentials and enable further access to compromised networks.

“Some threat actors have recently developed workarounds to current mitigations and detection methods and have been able to exploit weaknesses, move laterally, and escalate privileges without detection,” the agency said.

“CISA is aware of instances in which sophisticated threat actors have subverted the external integrity checker tool (ICT), further minimizing traces of their intrusion.”

Patch rollout

Ivanti released the first batch of patches for the two vulnerabilities on Wednesday but noted that patches for other supported versions will still be released on a staggered schedule.

“We are recommending as a best practice that all customers factory reset their appliance before applying the patch to prevent the threat actor from gaining upgrade persistence in your environment. Historically we have seen this threat actor attempt to gain persistence in customers’ environment, which is why we are recommending this action as a best practice for all customers,” the company said.

Security firm Mandiant — which worked alongside cybersecurity company Volexity in analyzing exploitation of the two bugs — released an updated blog confirming that hackers based in China are continuing to exploit the vulnerabilities.

Since their initial blog post, Mandiant incident responders said they have seen exploitation expand beyond Chinese espionage hackers to several other hacking operations. The company outlined the variety of backdoors and malware hackers are deploying after compromise in order to keep their access to breached systems.

Ken Dunham, cyber threat director at Qualys Threat Research Unit, said Ivanti is likely being targeted because of the functionality and architecture it provides actors. It provides hackers with access networks and downstream targets of interest, Dunham added.

“These Ivanti high-security flaws are serious and should be patched immediately. Vulnerabilities that enable users to elevate privileges to the administrator level or provide access to restricted resources without authentication have proven to be particularly valuable for attackers,” said Keeper Security’s Patrick Tiquet.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ivanti-warns-of-two-bugs-as-cisa-issues-alert-about-hackers