Ivanti devices hit by wave of exploits for latest security hole
ID: 031f281f-0a11-5b58-9c70-5cb86777acc5
STIX ID: report--031f281f-0a11-5b58-9c70-5cb86777acc5
Feed Name: The Register (Security)
Multiple threat actors are exploiting Ivanti’s CVE-2024-21893 SSRF flaw in Connect Secure and Policy Secure appliances, which can be chained with CVE-2024-21887 for unauthenticated root-level command injection, compounding prior issues with CVE-2023-46805. Following Rapid7’s public PoC, ShadowServer observed widespread exploitation and backdoor attempts from over 170 IPs. Ivanti has released patches for supported versions, while CISA issued an emergency directive requiring federal agencies to disconnect the affected products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
