CISA cautions against using hacked Ivanti VPN gateways even after factory resets
ID: 5c73b77b-28ab-5e32-9708-d258c876fbca
STIX ID: report--5c73b77b-28ab-5e32-9708-d258c876fbca
Feed Name: Bleeping Computer
**CISA advisory:** Multiple high-to-critical Ivanti Connect Secure and Policy Secure VPN vulnerabilities (including CVE-2023-46805, CVE-2024-21887, CVE-2024-22024, CVE-2024-21893) are being actively exploited to achieve authentication bypass, command injection, SSRF, and arbitrary command execution; attackers have been shown to gain root persistence that can survive factory resets and evade Ivanti's Integrity Checker Tool, leading CISA to advise aggressive remediation, hunting for IOCs, and order federal agencies to disconnect affected appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
