logo

Ivanti Pulse Secure Found Using 11-Year-Old Linux Version and Outdated Libraries

ID: 68e49e19-8fc9-5351-902c-70b8bef25a09

STIX ID: report--68e49e19-8fc9-5351-902c-70b8bef25a09

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-02-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Eclypsium's analysis of Ivanti Pulse Secure firmware (version 9.1.18.2-24467.1) reveals the product runs an outdated CentOS 6.4-based stack with thousands of cumulative vulnerabilities (including many with public exploits), numerous vulnerable libraries, outdated packages and certificates, and logic flaws in Ivanti's Integrity Checker Tool that exclude key directories from scanning. The report ties these findings to active exploitation and scanning of multiple Ivanti CVEs, demonstrates obtaining remote access via published PoCs and exporting device images for analysis, and highlights real-world risks: delivery of web shells, stealers, backdoors, tampering with integrity checks, and potential data staging/exfiltration from excluded paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.