Today, Ivanti warned of two more vulnerabilities impacting Connect Secure, Policy Secure, and ZTA gateways, one of them a zero-day bug already under active exploitation. The zero-day flaw (CVE-2024-21893) is a server-side request forgery vulnerability in the gateways' SAML component that enables attackers to bypass authentication and access restricted resources on vulnerable devices. A second flaw (CVE-2024-21888) in the gateways' web component allows threat actors to escalate privileges to those of an administrator. "As part of our ongoing investigation into the vulnerabilities reported on 10 January in Ivanti Connect Secure, Ivanti Policy Secure and ZTA gateways, we have discovered new vulnerabilities. These vulnerabilities impact all supported versions – Version 9.x and 22.x," the company said today. "We have no evidence of any customers being impacted by CVE-2024-21888 at this time. We are only aware of a small number of customers who have been impacted by CVE-2024-21893 at this time." "It is critical that you immediately take action to ensure you are fully protected," Ivanti warned. Ivanti has released security patches to address both flaws for some affected ZTA and Connect Secure versions, and it provides mitigation instructions for devices still waiting for a patch. The company also released patches today for two other zero-days disclosed in early January— an authentication bypass (CVE-2023-46805) and a command injection (CVE-2024-21887)—chained in widespread attacks ...
Ivanti warns of new Connect Secure zero-day exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Jan 31, 2024
·Updated
Affected Software
4 affected components
Ivanti Connect Secure=9.x
Ivanti Connect Secure=22.x
Ivanti Policy Secure
Ivanti ZTA gateways
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new zero-day vulnerability in Ivanti's Connect Secure and related products that is currently being exploited in attacks.
2
What security implications are discussed in this article?
The article highlights the risk of exploitation due to the discovered server-side request forgery vulnerability in Ivanti's software.
3
What specific vulnerabilities are mentioned in the article?
The article mentions a zero-day vulnerability identified as CVE-2024-21893, along with two additional vulnerabilities impacting Ivanti products.
4
What products or software are affected by the vulnerabilities?
Affected products include Ivanti Connect Secure (versions 9.x and 22.x), Ivanti Policy Secure, and Ivanti ZTA gateways.
5
What action should users of affected Ivanti products take?
Users of the affected Ivanti products are urged to apply available patches and monitor their systems for any unusual activity.