CISA orders Ivanti devices targeted by Chinese hackers be disconnected
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21887 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) |
Full article796 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
An updated emergency directive includes instructions on how to bring affected devices back online securely.
Any federal agency running Ivanti Connect Secure or Ivanti Policy Secure devices must disconnect them from their networks before midnight Friday, the United States’s top civilian cyber defense agency said Wednesday amid reports the vulnerable devices are being targeted by espionage operations linked to China.
Last month, CISA warned that the vulnerable Ivanti devices were subject to “widespread exploitation of vulnerabilities by multiple threat actors.” On Wednesday, the agency issued new instructions for how to update and bring those devices back online.
A CISA spokesperson did not immediately respond to a question about how many instances of Ivanti’s affected product are present in federal networks.
The CISA directive comes amid growing concern in Washington about Chinese cyberoperations. Separately on Wednesday, senior U.S. national security officials warned a Congressional panel that China’s aggressive cyber operations are not only aimed at gathering intelligence but also to preposition in critical civilian-focused U.S. networks in the event of military conflict.
Chinese hackers appear to be exploiting the Ivanti vulnerabilities to carry out espionage. Researchers with Google’s Mandiant wrote in a blog post Wednesday that they’d identified “broad exploitation activity” by suspected Chinese-linked espionage hackers they track as “UNC5221,” as well as other uncategorized attackers.
Cybersecurity experts said the CISA directive appeared aimed at definitively cutting off Ivanti devices as a way to target the U.S. government.
“I think what it largely boils down to is that CISA likely does not want to have ambiguity as to whether an Ivanti Connect Secure VPN appliance is compromised or not,” said Steven Adair, president of cybersecurity firm Volexity. “Given the multitude of vulnerabilities in the last month, the best way to go about that is to taken the systems offline, factory reset the device, start with a fresh build, and apply the latest patches.”
Ivanti has issued guidance on remediating issues with the devices based on the latest knowledge of how the attacks work. The company did not respond to a request for comment Thursday.
Last month — before CISA’s first directive regarding Ivanti devices — Adair and his team published research detailing what was then an “active in-the-wild exploitation” of two Ivanti vulnerabilities that made it “trivial for attackers to run commands on the system” and ultimately pivot to a handful of systems internally and gain “unfettered access to systems on the network.” That operation dates back to the second week of December 2023, according to the Volexity researchers.
“This is the first emergency directive issued by the Cybersecurity and Infrastructure Security Agency in almost two years, highlighting the criticality of the situation,” Glenn Thorpe, senior director of security research and detection engineering with Greynoise, told CyberScoop in an email Thursday.
Ron Bowes, Greynoise’s lead security researcher, added that Ivanti Connect Secure is designed to be internet-facing and to bridge the internet to a secure network, “which makes it a very good target.” Exploitation of one of the vulnerabilities — tracked as CVE-2024-21887 — is “quite simple,” Bowes said.
More than 85% of the known zero-day vulnerabilities exploited by Chinese state-sponsored hackers since 2021 were in public-facing appliances such as firewalls and VPN products, Recorded Future’s Insikt Group wrote in a November 2023 report.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ivanti-connect-secure-china/