Various miscreants are attempting to exploit the latest Ivanti flaw, a server-side request forgery (SSRF) vulnerability tracked as CVE-2024-21893 that can be used to hijack equipment. That's according to threat hunters tracking the string of CVE-listed security holes plaguing the VPN gateways in recent weeks. Ivanti on January 31 disclosed and began patching CVE-2024-21893, which is present in the SAML component of of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) appliances. The vendor spotted the flaw as it was investigating and scrambling to patch two other zero-day bugs in those products: an authentication bypass vulnerability (CVE-2023-46805), and a common injection flaw (CVE-2024-21887), both of which are also under attack. Crooks latched onto CVE-2024-21893 because the vulnerability can be used to bypass mitigation efforts for those pair of earlier flaws and gain control of network gateways. "At the time of publication, the exploitation of CVE-2024-21893 appears to be targeted," Ivanti claimed last week, adding that it expected exploitation to ramp up sharply as word of the security hole spread. "The SSRF can be chained to CVE-2024-21887 for unauthenticated command injection with root privileges," Rapid7 principal security researcher Stephen Fewer added on February 2. The security shop also published a proof-of-concept (PoC) exploit for CVE-2024-21893 that same day. And unsurprisingly, the infosec watchers at ShadowServer observed attempts to op...
Ivanti devices hit by wave of exploits for latest security hole
The Register
·Jessica Lyons
·Published Feb 5, 2024
·Updated
Affected Software
4 affected components
Ivanti Connect Secure=9.x
Ivanti Connect Secure=22.x
Ivanti Policy Secure=9.x
Ivanti Policy Secure=22.x
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a newly discovered vulnerability in Ivanti devices, specifically CVE-2024-21893.
2
What security implications are discussed in the article?
The main security implication is that the server-side request forgery (SSRF) vulnerability could allow attackers to hijack affected equipment.
3
What products are affected by this vulnerability?
The affected products include Ivanti Connect Secure and Ivanti Policy Secure.
4
Who is actively exploiting this Ivanti security flaw?
Various miscreants are attempting to exploit the identified vulnerability.
5
What is CVE-2024-21893?
CVE-2024-21893 is a server-side request forgery vulnerability that poses a significant risk to Ivanti VPN gateways.