rootpwn

Vulnerabilities

Ivanti Connect Secure & Policy Secure Gateways Hit by Multi‑Vulnerability Surge – Patch Now

A wave of critical flaws—CVE‑2024‑22024, CVE‑2024‑21888, CVE‑2024‑21893, CVE‑2023‑46805, CVE‑2024‑21887—has been actively exploited against Ivanti Connect Secure and Policy Secure Gateways. The bugs enable unauthenticated privilege escalation, SSRF, and remote code execution, letting attackers hijack devices and steal credentials. Ivanti released patches for most affected versions in February, with additional fixes rolled out through March. Immediate patching, re‑authentication, and hardened configuration are essential to stop attackers from leveraging these weaknesses.

Ivanti’s Pulse Connect Secure (ICS) and Policy Secure gateways have become a prime target for attackers, thanks to a flurry of newly discovered vulnerabilities that allow everything from privilege escalation to remote code execution. The exploits have already been weaponised in the wild, with threat actors using them to siphon credentials and gain full control over compromised devices.

What’s at stake?

  • CVE‑2024‑22024 – Unauthenticated access to restricted resources via a flaw in the authentication bypass mechanism.
  • CVE‑2024‑21888 – Privilege escalation on the web component, letting an attacker gain higher rights on the gateway.
  • CVE‑2024‑21893 – Server‑side request forgery (SSRF) through the SAML component, actively exploited to pivot into internal networks.
  • CVE‑2023‑46805 – Bypass of authentication entirely, enabling attackers to log in without credentials.
  • CVE‑2024‑21887 – Remote authenticated attacker can execute arbitrary commands on the host.

Who’s affected?

All versions of Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) are vulnerable, including the ZTA gateways. The list of vulnerable releases is extensive, covering legacy 9.x builds up to the latest 22.x and 23.x series.

Patch status

  • February 15: Patches released for 9.1R15.3, 9.1R16.3, 22.1R6.1, 22.2R4.1, 22.3R1.1, 22.4R1.1 (ICS) and 9.1R16.3, 22.4R1.1, 22.6R1.1 (IPS).
  • March 4: Updated guidance for virtual‑machine deployments and cluster configurations.
  • April 15: Latest advisory confirms all critical bugs are fixed in the newest 22.5R2.2 (ICS) and 22.5R1.1 (IPS) releases.

Immediate actions

  • Verify current firmware version and compare against the official Ivanti release matrix.
  • Apply the latest patches as soon as possible; for virtualised deployments, follow the specific VM remediation steps.
  • Re‑authenticate all users and rotate credentials that may have passed through vulnerable devices.
  • Enable multi‑factor authentication and restrict administrative access to a minimal set of trusted hosts.
  • Monitor logs for unusual authentication attempts, SSRF‑related traffic, and command‑execution patterns.
“If your organisation relies on Ivanti Connect Secure or Policy Secure, patching is non‑negotiable. The exploitation chain is already active, and the attackers are targeting credential harvesting and lateral movement.” – CERT‑FR advisory

For further guidance, consult the full Ivanti security bulletin and the CERT‑FR advisory series. Stay ahead of the attackers by keeping your gateways up to date and hardening your overall security posture.

Ivanti Remote Code Execution SSRF Privilege Escalation Patch Management Cyber Threats

← All news