• News/
  • https://www.theregister.com/2024/02/09/ivanti_discloses_fifth_ics_vulnerability/

Ivanti discloses fifth vulnerability, doesn't credit researchers who found it

The Register
·
Connor Jones
·
Published Feb 9, 2024
·
Updated

In disclosing yet another vulnerability in its Connect Secure, Policy Secure, and ZTA gateways, Ivanti has confused the third-party researchers who discovered it. Researchers at watchTowr blogged today about not being credited with the discovery of CVE-2024-22024 – the latest in a series of vulnerabilities affecting Ivanti gateways as the vendor continues to develop patches for supported versions. The high-severity authentication bypass flaw only affects a limited number of supported versions, unlike the zero-days that came before it, and, according to Ivanti, it was discovered in-house. "As part of the ongoing investigation, we discovered a new vulnerability as part of our internal review and testing of our code, which we are reporting as CVE-2024-22024," an Ivanti article reads. However, watchTowr claims its researchers were the first to bring Ivanti's attention to the bug on February 2, publishing screenshots of the emails exchanged between it and Ivanti as proof. Commenting on the above excerpt from Ivanti's advisory, watchTowr said: "Today, Friday February 9, 2024, we are pleased to see that Ivanti has released an advisory for this vulnerability. "We did find this comment a little curious, but perhaps we have a new set of colleagues?" It went on to say it was "surprised" about seeing the missing credit, but assumes it was done without malice. The vulnerability itself, to the delight of admins across the land, isn't as serious as the others that were disclosed over the pa...

Read full article

Affected Software

7 affected components
Ivanti Connect Secure=9.1R14.4
Ivanti Connect Secure=9.1R17.2
Ivanti Connect Secure=9.1R18.3
Ivanti Connect Secure=22.4R2.2
Ivanti Connect Secure=22.5R1.1
Ivanti Policy Secure=22.5R1.1
Ivanti ZTA=22.6R1.3

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the disclosure of a fifth vulnerability in Ivanti's security products.

2

What security implications are discussed?

The vulnerabilities could potentially expose users to security risks if not patched promptly.

3

What products or software are affected?

The affected products include Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti ZTA gateways.

4

Who discovered the vulnerabilities mentioned in the article?

The vulnerabilities were discovered by third-party researchers, although Ivanti did not credit them.

5

What versions of Ivanti products are impacted by the vulnerability?

Affected versions include multiple releases of Ivanti Connect Secure, Policy Secure, and ZTA from various releases noted in the article.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203