EXPOSURES › CVE-2024-21887
CVE-2024-21887
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIvanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances.
An authenticated administrator could send crafted requests to execute code on affected appliances, and this flaw was leveraged alongside CVE-2023-46805 to bypass authentication. DIB organizations must ensure these products are patched immediately, as the vulnerability is on CISA's KEV list and linked to ransomware attacks.
Shame score — The vulnerability was actively exploited in the wild, linked to ransomware, and represents a critical failure in patching a known, high-severity flaw in a widely deployed security product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |