CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-21887

CVSS 9.1v3.1pub. 2024-01-12upd. 2026-08-04

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

🤖 AI Analysis
How it works

An attacker with administrator privileges can send specially crafted requests to the device's web components. Injected commands are executed directly by the appliance's operating system without proper validation and sanitization of input data (CWE-77). Combined with CVE-2023-46805 vulnerability (authentication bypass) available in the same products, unauthenticated RCE is possible — as confirmed by publicly available exploits.

Impact

An attacker can execute arbitrary system commands on the device, which in practice means complete takeover of the appliance, including the ability to access sensitive data, modify configuration, and perform lateral movement through the network.

Mitigation & patch

Apply patches available from the vendor according to references (Ivanti forum: CVE-2023-46805 and CVE-2024-21887). Due to active exploitation of the vulnerability and availability of public exploits, the update should be performed immediately. It is also recommended to review logs for signs of compromise.

Who is affected

Ivanti Connect Secure versions 9.x and 22.x; Ivanti Policy Secure versions 9.x and 22.x

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ivanti Connect Secure

    APP
    Ivanti
    22.122.222.322.422.522.69.09.1
  • Ivanti Policy Secure

    APP
    Ivanti
    22.122.222.322.422.522.69.09.1

CISA KEV — detailsi

Vendori
Ivanti
Producti
Connect Secure and Policy Secure
Added to KEVi
January 10, 2024
Remediation deadline (US Federal)i
January 22, 2024(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 22 stycznia 2024
CWE
References

Related vulnerabilities

CVE-2025-22457CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE

CVE-2025-0282CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA

CVE-2021-22893CRITICAL10.0⚠ KEVPL ✓same product

Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE

CVE-2019-11510CRITICAL10.0⚠ KEVPL ✓same product

Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia

CVE-2024-10644CRITICAL9.1PL ✓same product

Code injection w Ivanti Connect Secure i Policy Secure — RCE