Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation
ID: 5c8c3831-a7d5-5897-a5b2-75e658129c61
STIX ID: report--5c8c3831-a7d5-5897-a5b2-75e658129c61
Feed Name: The Hacker News
Threat Score
A critical SSRF vulnerability in Ivanti Connect Secure and Policy Secure (CVE-2024-21893 / CVE-2023-36661) has been widely exploited in the wild—attackers are chaining it with other flaws (including CVE-2024-21887) to gain unauthenticated RCE and deploy web shells; thousands of instances were exposed and hundreds compromised, a public PoC increased exploitation activity, and vendors and EU security authorities issued mitigations and patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
