Connect Secure No More: Ivanti's Zero-Day Vulnerabilities (CVE-2024-21887 and CVE-2023-46805) | UpGuard
ID: a37303a2-1f82-58c8-957b-f3662c7aeb13
STIX ID: report--a37303a2-1f82-58c8-957b-f3662c7aeb13
Feed Name: UpGuard Blog
Two chainable zero-day vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure (CVE-2023-46805 — authentication bypass, and CVE-2024-21887 — command injection/RCE) have been actively exploited in the wild; attackers combined these flaws to achieve unauthenticated code execution, enabling credential theft, lateral movement, configuration changes, and deployment of multiple malware families, prompting CISA to add both to its Known Exploited Vulnerabilities catalog and vendors to publish mitigations and investigative guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
