Hackers are exploiting a server-side request forgery (SSRF) vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA gateways to deploy the new DSLog backdoor on vulnerable devices. The vulnerability, tracked as CVE-2024-21893, was disclosed as an actively exploited zero-day on January 31, 2024, with Ivanti sharing security updates and mitigation advice. The flaw impacts the SAML component of the mentioned products and allows attackers to bypass authentication and access restricted resources on Ivanti gateways running versions 9.x and 22.x. The updates that fix the problem are Ivanti Connect Secure versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1 and 22.5R2.2, Ivanti Policy Secure version 22.5R1.1, and ZTA version 22.6R1.3. On February 5, 2024, threat monitoring service Shadowserver reported seeing multiple attackers attempting to leverage the flaw, some using proof-of-concept (PoC) exploits previously published by Rapid7, with the success rate being unknown at the time. A new report by Orange Cyberdefense confirms the successful exploitation of CVE-2024-21893 to install a new backdoor named DSLog that allows the threat actors to execute commands on compromised Ivanti servers remotely. Orange says they first spotted this new backdoor on February 3, 2024, after analyzing a compromised appliance that had implemented the Ivanti-proposed XML mitigation (blocking all API endpoints) but hadn't applied the patch. By examining the compromised Invanti device's logs, Or...
Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor
BleepingComputer
·Bill Toulas
·Published Feb 12, 2024
·Updated
Affected Software
8 affected components
Ivanti Connect Secure=9.1R14.4
Ivanti Connect Secure=9.1R17.2
Ivanti Connect Secure=9.1R18.3
Ivanti Connect Secure=22.4R2.2
Ivanti Connect Secure=22.5R1.1
Ivanti Connect Secure=22.5R2.2
Ivanti Policy Secure=22.5R1.1
Ivanti ZTA=22.6R1.3
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a server-side request forgery (SSRF) vulnerability in Ivanti software that allows hackers to deploy a backdoor.
2
What security implications are discussed?
The security implications include the ability for attackers to gain unauthorized access and control over vulnerable Ivanti devices.
3
What vulnerability is being exploited by hackers?
Hackers are exploiting a vulnerability tracked as CVE-2024-21893.
4
What products or software are affected by this vulnerability?
The affected Ivanti products include Connect Secure, Policy Secure, and ZTA gateways.
5
Which versions of Ivanti products are known to be vulnerable?
Vulnerable versions include specific releases of Ivanti Connect Secure, Policy Secure, and ZTA as listed in the article.