CISA Emergency Directive Orders Action on Ivanti Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) |
Full article309 words · extracted from infosecurity-magazine.com · click to collapse
A leading US security agency has issued an emergency directive requiring all of the government’s civilian federal agencies to mitigate two zero-days under active exploitation.
Emergency Directive 24-01 was issued on Friday in response to “widespread and active exploitation of vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure.”
CISA director, Jen Easterly, argued that the vulnerabilities pose “significant, unacceptable risks” not only to government agencies but all organizations.
“As America’s cyber-defense agency and the operational lead for federal civilian cybersecurity, we must take urgent action to reduce risks to the federal systems upon which Americans depend,” she added.
“Even as federal agencies take urgent action in response to this directive, we know that these risks extend to every organization and sector using these products. We strongly urge all organizations to adopt the actions outlined in this directive.”
Read more on Ivanti zero-days: Ivanti Patches Zero-Day Bug Used in Norway Attacks
Ivanti first disclosed the vulnerabilities on January 10, although it’s believed they had been under active exploitation by a Chinese state actor since December 3.
When chained, CVE-2023-46805 and CVE-2024-21887 enable threat actors to craft malicious requests and execute arbitrary commands on the system, without needing to authenticate first.
Last week, researchers at Volexity revealed that the bugs were under active exploitation by a number of threat groups, with over 1700 devices already compromised.
Patches from security vendor Ivanti are slated to start rolling out this week, but the firm has also released a mitigation, which CISA has requested impacted organizations download.
“This directive requires agencies to implement Ivanti’s published mitigation immediately to the affected products in order to prevent future exploitation,” it noted.
“As this initial action does not remedy an active or past compromise, agencies are also required to run Ivanti’s External Integrity Checker Tool and take additional steps if indications of compromise are detected.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-emergency-directive-action/