Approximately 16,500 Ivanti Connect Secure and Poly Secure gateways exposed on the internet are likely vulnerable to a remote code execution (RCE) flaw the vendor addressed earlier this week. The flaw is tracked as CVE-2024-21894 and is a high-severity heap overflow in the IPSec component of Ivanti Connect Secure 9.x and 22.x, potentially allowing unauthenticated users to cause denial of service (DoS) or achieve RCE by sending specially crafted requests. Upon disclosure, on April 3, 2024, the internet search engine Shodan showed 29,000 internet-exposed instances, while threat monitoring service Shadowserver reported seeing roughly 18,000. At the time, Ivanti stated that it had seen no signs of active exploitation in any of its customers but urged system administrators to apply the updates as soon as possible. Two days later, Shadowserver added CVE-2024-21894 into its scanning capabilities, reporting that about 16,500 instances are vulnerable to the RCE flaw. Most of those instances (4,700) are in the United States, with Japan (2,000), the UK (1,000), Germany (900), France (900), China (500), the Netherlands (500), Spain (500), Canada (330), India (330), and Sweden (320) following with significant level of exposure too. High-risk vulnerabilities in Ivanti products often act as a point of breach for organizations worldwide. Earlier this year, it was revealed that state-sponsored threat actors leveraged multiple flaws in Ivanti products, namely CVE-2023-46805, CVE-2024-21887, C...
New Ivanti RCE flaw may impact 16,000 exposed VPN gateways
BleepingComputer
·Bill Toulas
·Published Apr 5, 2024
·Updated
Affected Software
2 affected components
Ivanti Connect Secure=9.x
Ivanti Connect Secure=22.x
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly discovered remote code execution (RCE) flaw affecting Ivanti VPN gateways.
2
What vulnerability is highlighted in the article?
The highlighted vulnerability is tracked as CVE-2024-21894, which could allow remote code execution.
3
How many VPN gateways are potentially affected by this flaw?
Approximately 16,500 Ivanti Connect Secure and Poly Secure gateways are potentially affected by this vulnerability.
4
Which specific software versions are mentioned as vulnerable?
The vulnerable versions of Ivanti Connect Secure are 9.x and 22.x.
5
What action has the vendor taken regarding the vulnerability?
The vendor has addressed the flaw earlier this week, though details on the patch are not provided in the article.