Skip to content
COOEY

EXPOSURES › CVE-2024-21887

CVE-2024-21887

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-21887 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances.

An authenticated administrator could send crafted requests to execute code on affected appliances, and this flaw was leveraged alongside CVE-2023-46805 to bypass authentication. DIB organizations must ensure these products are patched immediately, as the vulnerability is on CISA's KEV list and linked to ransomware attacks.

Shame score — The vulnerability was actively exploited in the wild, linked to ransomware, and represents a critical failure in patching a known, high-severity flaw in a widely deployed security product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized