WARNING: IVANTI RELEASES SECURITY UPDATE TO ADRESS VULNERABILITIES IN IVANTI CONNECT SECURE, IVANTI POLICY SECURE GATEWAYS!
ID: f90b149c-8ce3-5baa-ad84-5e3e1678b1b1
STIX ID: report--f90b149c-8ce3-5baa-ad84-5e3e1678b1b1
Ivanti and national cybersecurity partners have published an advisory for multiple severe vulnerabilities in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA — including an actively exploited authentication bypass (CVE-2023-46805) and a command-injection vulnerability (CVE-2024-21887) that, together with additional flaws (CVE-2024-21888, CVE-2024-21893, CVE-2024-22024), can allow unauthenticated access, remote command execution, privilege escalation, and SSRF/XXE; administrators are urged to apply vendor patches or mitigations immediately and increase detection and incident reporting capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
