ZeroHour
The Recordpublished ()ingested

All federal civilian agencies ordered to disconnect at

mediumVulnerabilityimportance 35CVE-2024-21893

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21893
SSRF in Ivanti Connect Secure, Policy Secure, and Neurons SAML Component

CVE-2024-21893 is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (formerly Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons. A remote attacker can trigger the flaw with crafted unauthenticated requests to the SAML component, causing the appliance to make requests to otherwise restricted resources. Successful exploitation allows the attacker to access certain restricted resources without any credentials, and CISA notes the flaw has been used in ransomware operations. Any organization running an affected Ivanti Connect Secure, Policy Secure, or Neurons deployment is exposed, particularly where the appliance is reachable from the internet. The vulnerability is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-31, carries an EPSS probability of 100%, and no public proof-of-concept is known.

Do: Apply Ivanti's released patches or the vendor-issued mitigations immediately per vendor instructions, or discontinue use of the product if mitigations are unavailable, as required by CISA. Because ransomware use is documented, review SAML-related logs and appliance audit trails for signs of exploitation and follow-on compromise, and check for indicators of post-exploitation activity. Monitor Ivanti advisories for patched version numbers and updated mitigation guidance, since specific fixed versions are not yet specified in the available data.

8.2100% KEV ransomware
  • Ivanti Connect Secure (formerly Pulse Connect Secure)
  • Ivanti Policy Secure
  • Ivanti Neurons
largetens of thousands of internet-exposed appliances (with total user counts likely in the hundreds of thousands)
Full article315 words · extracted from therecord.media · click to collapse

All federal civilian agencies in the U.S. have been ordered to disconnect Ivanti Connect Secure and Policy Secure products by Friday after more vulnerabilities were found in the tools this week.

In an updated directive published on Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) gave agencies until Friday at midnight to remove the tools from their networks and until midnight on Monday to confirm that they had done so.

“Agencies running the affected products must assume domain accounts associated with the affected products have been compromised,” CISA said.

By March 1, agencies have to take a range of technical actions on their network and similarly report it all to CISA.

CISA officials previously told reporters that there are “around 15 agencies that were using these products” but declined to confirm if any dealt with compromises. The agencies using the tools cover “a wide spectrum … across the breadth of the federal mission,” an official said.

CISA said it has “observed some initial targeting of federal agencies” and is investigating each situation.

Ivanti announced on Wednesday that two new vulnerabilities were discovered and CISA said it had seen hackers shift their tactics since the initial mitigation guidance was issued early last month.

Ivanti said “a small number of customers” have been impacted by one of the new vulnerabilities – tagged as CVE-2024-21893.

Mandiant has conducted several incident response investigations and explained in a blog post that most of the initial exploitation was done by espionage threat actors allegedly based in China. Since the bugs were first announced, exploitation has expanded to cybercriminals and others.

Cybersecurity research firm Censys said that as of January 22, over 26,000 unique Connect Secure hosts are exposed on the public internet.

Ivanti released the first batch of patches for the two vulnerabilities on Wednesday but noted that patches for other supported versions will still be released on a staggered schedule.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/federal-civilian-agencies-ordered-to-disconnect-at-risk-ivanti-products-cisa