Ivanti Connect Secure/Policy Secure CVE-2023-46805, CVE-2024-21887 Combine for Unauthenticated RCE, and following CVEs discovered over time
ID: 106b15de-4a2b-50e0-9d15-84ac27c7b291
STIX ID: report--106b15de-4a2b-50e0-9d15-84ac27c7b291
Feed Name: Kudelski Security
Kudelski Security reports multiple critical vulnerabilities in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA (including CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893, and CVE-2024-22024) that enable authentication bypass, command injection, privilege escalation, SSRF, and XXE; the flaws impact supported 9.x and 22.x releases, have high CVSS scores, and are being actively exploited by a state-sponsored APT and opportunistic actors, so immediate patching or application of Ivanti's XML mitigation is strongly recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
