• News/
  • https://www.bleepingcomputer.com/news/security/new-ivanti-rce-flaw-may-impact-16-000-exposed-vpn-gateways/

New Ivanti RCE flaw may impact 16,000 exposed VPN gateways

BleepingComputer
·
Bill Toulas
·
Published Apr 5, 2024
·
Updated

Approximately 16,500 Ivanti Connect Secure and Poly Secure gateways exposed on the internet are likely vulnerable to a remote code execution (RCE) flaw the vendor addressed earlier this week. The flaw is tracked as CVE-2024-21894 and is a high-severity heap overflow in the IPSec component of Ivanti Connect Secure 9.x and 22.x, potentially allowing unauthenticated users to cause denial of service (DoS) or achieve RCE by sending specially crafted requests. Upon disclosure, on April 3, 2024, the internet search engine Shodan showed 29,000 internet-exposed instances, while threat monitoring service Shadowserver reported seeing roughly 18,000. At the time, Ivanti stated that it had seen no signs of active exploitation in any of its customers but urged system administrators to apply the updates as soon as possible. Two days later, Shadowserver added CVE-2024-21894 into its scanning capabilities, reporting that about 16,500 instances are vulnerable to the RCE flaw. Most of those instances (4,700) are in the United States, with Japan (2,000), the UK (1,000), Germany (900), France (900), China (500), the Netherlands (500), Spain (500), Canada (330), India (330), and Sweden (320) following with significant level of exposure too. High-risk vulnerabilities in Ivanti products often act as a point of breach for organizations worldwide. Earlier this year, it was revealed that state-sponsored threat actors leveraged multiple flaws in Ivanti products, namely CVE-2023-46805, CVE-2024-21887, C...

Read full article

Affected Software

2 affected components
Ivanti Connect Secure=9.x
Ivanti Connect Secure=22.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered remote code execution (RCE) flaw affecting Ivanti VPN gateways.

2

What vulnerability is highlighted in the article?

The highlighted vulnerability is tracked as CVE-2024-21894, which could allow remote code execution.

3

How many VPN gateways are potentially affected by this flaw?

Approximately 16,500 Ivanti Connect Secure and Poly Secure gateways are potentially affected by this vulnerability.

4

Which specific software versions are mentioned as vulnerable?

The vulnerable versions of Ivanti Connect Secure are 9.x and 22.x.

5

What action has the vendor taken regarding the vulnerability?

The vendor has addressed the flaw earlier this week, though details on the patch are not provided in the article.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203