Critical Vulnerabilities in Ivanti Exploited in-the-Wild: everything you need to know
ID: a6aeadda-0a74-5d2e-8de7-3c1b6382efc6
STIX ID: report--a6aeadda-0a74-5d2e-8de7-3c1b6382efc6
Feed Name: Wiz Blog
Ivanti disclosed multiple high-severity vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 and CVE-2024-22024) affecting Ivanti Connect Secure, Ivanti Policy Secure and ZTA gateways that allow authentication bypass, SSRF, command injection, privilege escalation and potential remote code execution; several were exploited in the wild (reported as 0-days) by a suspected China-aligned espionage group (UNC5221/UTA0178) beginning in December 2023. Ivanti has released patches and workarounds, CISA mandated disconnection and remediation for federal agencies, and the report urges urgent patching, threat hunting and scanning for related IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
