Ivanti Patches Critical Flaws in Connect Secure and Policy Secure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-22467 +1 in the same advisory: …10644 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution. A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution. NVD description · AI analysis pending | 8.8 group max | 5% |
| — | ||
| CVE-2024-38657 | External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files. NVD description · AI analysis pending | 4.9 | 2% |
| — | ||
| CVE-2024-46668 +1 in the same advisory: …46666 | An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2024-47908 | OS Command Injection in Ivanti Cloud Services Appliance Admin Console Enables Admin RCE CVE-2024-47908 is an OS command injection flaw (CWE-78) in the admin web console of Ivanti's Cloud Services Appliance (CSA), fixed in version 5.0.5. A remote attacker who has authenticated with administrator privileges to the console can inject operating system commands and achieve remote code execution on the appliance. Because the console is typically reachable over the network and high-privileged credentials are the only barrier, risk depends heavily on admin credential hygiene and how widely the admin interface is exposed. All CSA deployments running versions before 5.0.5 are affected. There is no known public proof-of-concept and the flaw is not yet in the CISA KEV catalog, so no confirmed in-the-wild exploitation is currently documented, though EPSS assigns a fairly high ~22% probability of exploitation within 30 days. Do: Upgrade Ivanti CSA to version 5.0.5 or later as the primary remediation. Until patched, restrict access to the admin web console to trusted management networks (VPN/allowlist), enforce strong and unique admin credentials with MFA where available, and review appliance logs for unusual commands or unexpected admin sessions. Monitor Ivanti advisories, as the vendor has recently patched multiple CSA and Connect Secure issues and exploitation activity may follow. | 7.2 | 22% |
| moderateplausibly on the order of thousands of deployed CSA appliances (1k–10k range), many internet-exposed | ||
| CVE-2024-53704 | Authentication Bypass in SonicWall SonicOS SSLVPN CVE-2024-53704 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in the SSLVPN authentication mechanism of SonicWall's SonicOS. A remote, unauthenticated attacker can exploit it over the network without user interaction, bypassing SSLVPN authentication to gain unauthorized access to the VPN and a foothold into protected internal networks. CISA notes known ransomware use, making this a high-value entry point for follow-on attacks. Any organization running SonicWall SonicOS with SSLVPN enabled is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-18, public scans show 5,000+ internet-exposed SonicWall firewalls still unpatched, and EPSS rates the 30-day exploitation probability at 95.1%. Do: Upgrade affected SonicOS deployments to the patched releases listed in SonicWall's advisory, prioritizing internet-facing SSLVPN endpoints. Until patched, restrict or disable SSLVPN exposure where feasible and hunt for signs of exploitation, since ransomware use is known. Remediation must satisfy CISA KEV required actions (apply vendor mitigations or discontinue use). | 9.8 | 95% | KEV ransomware |
| largeestimated tens of thousands of SSLVPN-enabled SonicWall firewall deployments, with at least ~5,000 confirmed still exposed and unpatched on the public internet | |
| CVE-2024-55591 | Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it. Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching. | 9.8 | 98% | KEV ransomware |
| large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands | |
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) | |
| CVE-2025-24472 | Authentication Bypass in Fortinet FortiOS and FortiProxy Grants Super-Admin Access CVE-2025-24472 is an authentication bypass (CWE-288) in the Fortinet Security Fabric of FortiOS and FortiProxy. A remote, unauthenticated attacker who already knows the serial numbers of both the upstream and downstream devices can send crafted CSF proxy requests to gain super-admin privileges on the downstream device; the attack only works where the Security Fabric is enabled, and the need for serial-number knowledge raises attack complexity. An attacker gains full super-admin control of the downstream Fortinet device, which can serve as a foothold for network-wide compromise. Organizations running affected FortiOS 7.0.x or FortiProxy 7.0.x/7.2.x builds with Security Fabric enabled are in scope. The flaw was added to CISA's KEV catalog on 2025-03-18 with known ransomware use, and multiple ransomware groups (including Gunra, SuperBlack, Mora_001 and Qilin operators) have been reported exploiting Fortinet firewall flaws in recent campaigns. Do: Upgrade FortiOS 7.0.x and FortiProxy 7.0.x/7.2.x deployments to the fixed releases listed in the Fortinet PSIRT advisory for CVE-2025-24472, and identify any devices where the Security Fabric is enabled and serial numbers of peer devices may be discoverable. As interim mitigation, restrict or disable Security Fabric (CSF) connectivity toward untrusted peers and limit access to the CSF proxy handling path. Because the flaw is KEV-listed with known ransomware use, federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use, and all defenders should review device logs for unexpected super-admin sessions and anomalous CSF proxy traffic. | 8.1 | 7% | KEV ransomware |
| masshundreds of thousands of deployed Fortinet appliances plausibly affected; the practical subset is those with Security Fabric enabled |
Full article833 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 12, 2025Network Security / Vulnerability
Ivanti has released security updates to address multiple security flaws impacting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA) that could be exploited to achieve arbitrary code execution.
The list of vulnerabilities is below -
- CVE-2024-38657 (CVSS score: 9.1) - External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files
- CVE-2025-22467 (CVSS score: 9.9) - A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution
- CVE-2024-10644 (CVSS score: 9.1) - Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution
- CVE-2024-47908 (CVSS score: 9.1) - Operating system command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution
The shortcomings have been addressed in the below versions -
- Ivanti Connect Secure 22.7R2.6
- Ivanti Policy Secure 22.7R1.3
- Ivanti CSA 5.0.5
The company said it's not aware of any of the flaws being exploited in the wild. However, with Ivanti appliances being repeatedly weaponized by malicious actors, it's imperative that users take steps to apply the latest patches.
JPCERT/CC, in a report published today, revealed that it observed CVE-2025-0282 – a now-patched vulnerability affecting Ivanti Connect Secure – being exploited to deliver an updated version of the SPAWN malware framework called SPAWNCHIMERA.
"SPAWNCHIMERA is a malware that combines the updated functions of SPAWNANT, SPAWNMOLE, and SPAWNSNAIL into one," security researcher Yuma Masubuchi said, adding the modifications include changes to inter-process communication to use UNIX domain sockets and a function to plug the security defect in an attempt to prevent other actors from exploiting it.
Ivanti also acknowledged that its edge products have been "targeted and exploited by sophisticated threat actor attacks" and that it's making efforts to improve its software, implement secure-by-design principles, and raise the bar for potential abuse by adversaries.
"While these products are not the ultimate target, they are increasingly the route that well-resourced nation state groups are focusing their effort on to attempt espionage campaigns against extremely high-value organizations," Ivanti CSO Daniel Spicer said.
"We have enhanced internal scanning, manual exploitation and testing capabilities, increased collaboration and information sharing with the security ecosystem, and further enhanced our responsible disclosure process, including becoming a CVE Numbering Authority."
The development comes as Bishop Fox released full technical details of a now-patched security flaw in SonicWall SonicOS (CVE-2024-53704) that could be exploited to bypass authentication in firewalls and allow attackers to hijack active SSL VPN sessions in order to gain unauthorized access.
As of February 7, 2025, nearly 4,500 internet-facing SonicWall SSL VPN servers remain unpatched against CVE-2024-53704.
In a similar move, Akamai has published its discovery of two vulnerabilities in Fortinet FortiOS (CVE-2024-46666 and CVE-2024-46668) that an unauthenticated attacker can exploit to achieve denial-of-service (DoS) and remote code execution. The flaws were resolved by Fortinet on January 14, 2025.
Fortinet has since also revised its advisory for CVE-2024-55591 to highlight another flaw tracked as CVE-2025-24472 (CVSS score: 8.1) that could result in an authentication bypass in FortiOS and FortiProxy devices via a specially crafted CSF proxy request.
The company credited watchTowr Labs researcher Sonny Macdonald for discovering and reporting the flaw. It's worth noting that the vulnerability has already been patched alongside CVE-2024-55591, meaning no customer action is required if fixes for the latter have already been applied.
"Both CVEs cover the same vulnerability but on a different endpoint," Benjamin Harris, CEO of watchTowr, told The Hacker News. "There is one management interface, however this management interface has effectively three sub interfaces.
"The original CVE-2024-55591 vulnerability was scoped to an authentication bypass in only one of these sub interfaces. The 'new' CVE that was disclosed yesterday reflects the same authentication bypass in a different sub interface. The root cause is the same and the same patch resolves CVE-2025-24472."
Update
Cybersecurity company Arctic Wolf has disclosed that it's observing exploitation attempts of CVE-2024-53704, shortly after a proof-of-concept (PoC) was made available by Bishop Fox.
"The released PoC exploit allows an unauthenticated threat actor to bypass MFA, disclose private information, and interrupt running VPN sessions," researcher Andres Ramos said, describing the flaw as easy to exploit.
Thousands of Internet Exposed Ivanti Instances Online
According to data shared by Censys, there are an estimated 33,232 exposed Ivanti Connect Secure and Ivanti CSA instances online. However, it bears noting that not all instances are necessarily vulnerable given the lack of visibility into the specific versions installed.
(The story was updated after publication to include a response from watchTowr Labs.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/ivanti-patches-critical-flaws-in.html