Today, Ivanti warned of a new authentication bypass vulnerability impacting Connect Secure, Policy Secure, and ZTA gateways, urging admins to secure their appliances immediately. The flaw (CVE-2024-22024) is due to an XXE (XML eXternal Entities) weakness in the gateways' SAML component that lets remote attackers gain access to restricted resources on unpatched appliances in low-complexity attacks without requiring user interaction or authentication. "We have no evidence of any customers being exploited by CVE-2024-22024. However, it is critical that you immediately take action to ensure you are fully protected," Ivanti said. "For users of other supported versions, the mitigation released on 31 January successfully blocks the vulnerable endpoints until remaining patches are released," the company added in a separate advisory. Threat monitoring platform Shadowserver currently tracks over 20,000 ICS VPN gateways exposed online, with over 6,000 in the United States (Shodan currently tracks over 26,000 Internet-exposed Ivanti ICS VPNs). Shadowserver also monitors Ivanti Connect Secure VPN instances compromised worldwide daily, with almost 250 compromised devices discovered on Wednesday, February 7. Ivanti VPN appliances have been targeted in attacks chaining the CVE-2023-46805 authentication bypass and the CVE-2024-21887 command injection flaws as zero-days since December 2023. The company warned of a third actively exploited zero-day (a server-side request forgery vulnerability ...
Ivanti: Patch new Connect Secure auth bypass bug immediately
BleepingComputer
·Sergiu Gatlan
·Published Feb 8, 2024
·Updated
Affected Software
3 affected components
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti ZTA gateways
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly identified authentication bypass vulnerability in Ivanti's Connect Secure, Policy Secure, and ZTA gateways.
2
What is the identified vulnerability's CVE number?
The vulnerability is identified as CVE-2024-22024.
3
What type of vulnerability is reported in the article?
The reported vulnerability is an XML eXternal Entity (XXE) injection issue.
4
What products are affected by this security flaw?
The affected products are Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti ZTA gateways.
5
What action does Ivanti urge administrators to take?
Ivanti urges administrators to patch their appliances immediately to mitigate the vulnerability.