• News/
  • https://www.bleepingcomputer.com/news/security/newest-ivanti-ssrf-zero-day-now-under-mass-exploitation/

Newest Ivanti SSRF zero-day now under mass exploitation

BleepingComputer
·
Bill Toulas
·
Published Feb 5, 2024
·
Updated

An Ivanti Connect Secure and Ivanti Policy Secure server-side request forgery (SSRF) vulnerability tracked as CVE-2024-21893 is currently under mass exploitation by multiple attackers. Ivanti first warned about the flaw in the gateway's SAML components on January 31, 2024, giving it a zero-day status for limited active exploitation, impacting a small number of customers. Exploitation of CVE-2024-21893 allowed attackers to bypass authentication and access restricted resources on vulnerable devices (versions 9.x and 22.x). Threat monitoring service Shadowserver is now seeing multiple attackers leveraging the SSRF bug, with 170 distinct IP addresses attempting to exploit the flaw.

The exploitation volume of this particular vulnerability is far greater than that of other recently fixed or mitigated Ivanti flaws, indicating a clear shift in the attackers' focus. Although the proof-of-concept (PoC) exploit released by Rapid7 researchers on February 2, 2024, has undoubtedly played a role in assisting attacks, Shadowserver notes that they saw attackers using similar methods hours prior to the publication of the Rapid7 report. This means that hackers had already figured out how to leverage CVE-2024-21893 for unrestricted, unauthenticated access to vulnerable Ivanti endpoints. According to ShadowServer, there are currently almost 22,500 Ivanti Connect Secure devices exposed on the Internet. However, it is unknown how many are vulnerable to this particular vulnerability. The disclosur...

Read full article

Affected Software

2 affected components
Ivanti Connect Secure=9.x
Ivanti Connect Secure=22.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a server-side request forgery (SSRF) zero-day vulnerability in Ivanti products that is currently being exploited.

2

What security implications are discussed?

The article highlights the mass exploitation of the CVE-2024-21893 vulnerability, which could lead to unauthorized access and data breaches.

3

What products are affected by this vulnerability?

The vulnerability affects Ivanti Connect Secure versions 9.x and 22.x, as well as Ivanti Policy Secure.

4

What actions should affected users take?

Affected users should prioritize applying any available security patches from Ivanti as soon as possible to mitigate the risk.

5

Who is exploiting the vulnerability?

The article indicates that multiple attackers are currently exploiting the vulnerability, suggesting a widespread threat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203