Ivanti warns of Connect Secure zero-days exploited in attacks
ID: 39cf5081-2ca0-5b2d-bbf7-03371ffa2213
STIX ID: report--39cf5081-2ca0-5b2d-bbf7-03371ffa2213
Feed Name: Bleeping Computer
Ivanti disclosed two zero-day vulnerabilities in Connect Secure and Policy Secure appliances—an authentication bypass (CVE-2023-46805) and a command injection (CVE-2024-21887)—that have been observed exploited in the wild, reportedly by a suspected Chinese state-backed actor; when chained they allow unauthenticated remote code execution across supported appliances, mitigations (XML-based) are available while vendor patches are being staged, and thousands of gateways remain internet-exposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
