A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
An attacker with administrator privileges can send specially crafted requests to the device's web components. Injected commands are executed directly by the appliance's operating system without proper validation and sanitization of input data (CWE-77). Combined with CVE-2023-46805 vulnerability (authentication bypass) available in the same products, unauthenticated RCE is possible — as confirmed by publicly available exploits.
An attacker can execute arbitrary system commands on the device, which in practice means complete takeover of the appliance, including the ability to access sensitive data, modify configuration, and perform lateral movement through the network.
Apply patches available from the vendor according to references (Ivanti forum: CVE-2023-46805 and CVE-2024-21887). Due to active exploitation of the vulnerability and availability of public exploits, the update should be performed immediately. It is also recommended to review logs for signs of compromise.
Ivanti Connect Secure versions 9.x and 22.x; Ivanti Policy Secure versions 9.x and 22.x
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HIvanti Connect Secure
APPIvanti22.122.222.322.422.522.69.09.1Ivanti Policy Secure
APPIvanti22.122.222.322.422.522.69.09.1
CISA KEV — detailsi
- Vendori
- Ivanti ↗
- Producti
- Connect Secure and Policy Secure
- Added to KEVi
- January 10, 2024
- Remediation deadline (US Federal)i
- January 22, 2024(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
Related vulnerabilities
Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE
Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA
Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE
Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia
Code injection w Ivanti Connect Secure i Policy Secure — RCE