Update 4/5/25: ShadowServer says there are 16,000 exposed devices likely vulnerable to this flaw. IT security software company Ivanti has released patches to fix multiple security vulnerabilities impacting its Connect Secure and Policy Secure gateways. Unauthenticated attackers can exploit one of them, a high-severity flaw tracked as CVE-2024-21894, to gain remote code execution and trigger denial of service states on unpatched appliances in low-complexity attacks that don't require user interaction. The vulnerability is caused by a heap overflow weakness in the IPSec component of all supported gateway versions. While Ivanti said the remote code execution risks are limited to "certain conditions," the company didn't provide details on the vulnerable configurations. "We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure," Ivanti added. Today, the company also patched three other security flaws, impacting the same products and exploitable by unauthenticated threat actors for DoS attacks: Ivanti provides detailed instructions in this Knowledge Base Article on accessing and applying today's security patches. Shodan, a search engine used to discover Internet-exposed services and devices, currently tracks over 29,000 Ivanti Connect Secure VPN gateways exposed online, while threat monitoring platform Shadowserver sees over 18,000. Nation-state actors have been exploiting multiple vulnerabilities in Ivanti software this year, and thousa...
Ivanti fixes VPN gateway vulnerability allowing RCE, DoS attacks
BleepingComputer
·Sergiu Gatlan
·Published Apr 3, 2024
·Updated
Affected Software
2 affected components
Ivanti Connect Secure
Ivanti Policy Secure
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a recently fixed vulnerability in Ivanti's VPN gateway that allows for remote code execution and denial-of-service attacks.
2
What security implications are discussed in the article?
The vulnerabilities could potentially allow attackers to exploit remote code execution (RCE) and conduct denial-of-service (DoS) attacks.
3
What products are affected by the vulnerability?
The vulnerability affects Ivanti's Connect Secure and Policy Secure products.
4
How many devices are estimated to be vulnerable according to the article?
Approximately 16,000 exposed devices are likely vulnerable to this flaw.
5
What has Ivanti done in response to this vulnerability?
Ivanti has released patches to address the multiple security vulnerabilities impacting their products.