LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-21887: Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 22, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-21887 to its Known Exploited Vulnerabilities catalog on Jan 10, 2024, with a federal patch deadline of Jan 22, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an…

CVE-2024-21887 is a command injection vulnerability in the web components of Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure. An authenticated administrator can send crafted requests that result in code execution on the affected appliance. The issue can be leveraged together with CVE-2023-46805, an authentication bypass, which expands the practical attack surface.

These appliances commonly serve as remote-access and policy-enforcement gateways, so successful exploitation can give an attacker control of a high-value network entry point. The vulnerability has been observed in ransomware operations, making prompt assessment and remediation essential for any organization running the products.

How it works

The flaw is categorized as CWE-77 (improper neutralization of special elements used in a command). Within the web components of the listed Ivanti products, an authenticated administrator can craft requests that inject operating-system commands. Because the injection occurs in a privileged context on the appliance itself, the result is arbitrary code execution.

When chained with the related authentication-bypass issue, an attacker who has not yet obtained legitimate administrative credentials may still reach the vulnerable functionality. Exact request formats and payload construction are not detailed here; defenders must consult the vendor advisory for any technical indicators or proof-of-concept descriptions that have been released.

Am I affected? How to find it in your systems

Ivanti Connect Secure and Policy Secure typically appear as dedicated network appliances or virtual appliances that provide SSL VPN, remote-access, and access-policy services. They are frequently placed at the network edge or in DMZ segments.

How to remediate

The primary action is to apply the mitigations or software updates supplied by Ivanti, exactly as described in the vendor advisory. CISA’s required action is to apply those vendor mitigations or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls that limit both reachability and the impact of any successful injection.

If your data may have been exposed

Vulnerabilities that are actively exploited and known to be used in ransomware campaigns frequently lead to broader network compromise and data theft. Organizations that discover evidence of exploitation should treat the incident as a potential breach, preserve forensic artifacts, and follow their incident-response plan. Separately, individuals can run a free exposure scan of their email addresses against publicly known breach data sets to determine whether personal credentials have already appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Connect Secure and Policy Secure
WeaknessCWE-77
Added to CISA KEVJan 10, 2024
Federal patch deadlineJan 22, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities