CyberzSOC

Publication detail
← Back to advisories & guidance

Updated: New Software Updates and Mitigations to Defend Against Exploitation of Ivanti Connect Secure and Policy Secure Gateways ↗ source

January 30, 2024 CISA Alert

Summary

On Feb. 14, 2024, Ivanti released new software updates for Ivanti Connect Secure and Ivanti Policy Secure. An newly disclosed XML external entity injection (XXE) vulnerability (CVE-2024-22024) affecting: Connect Secure supported versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.5R2.2 Policy Secure supported versions 22.5R1.1 and ZTA version 22.6R1.3 Connect Secure supported versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.5R2.2 Policy Secure supported versions 22.5R1.1 and ZTA version 22.6R1.3 A cyber threat actor could exploit CVE-2024-22024 to take control of an affected system. Ivanti’s KB article includes software updates that cover this vulnerability. Additionally, on Feb. 8, 2024, Ivanti released software updates for all previously reported Ivanti Connect Secure and Policy Secure Gateways vulnerabilities in Ivanti devices ( CVE-2024-21888 , CVE-2024-21893 , CVE-2023-46805 , and CVE-2024-21887 ). See the KB article for specific guidance on implementing the updates. Additionally, CISA has issued version 2 of its Supplemental Direction to its Emergency Directive on Ivanti Vulnerabilities .

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-21887 9.1 Critical Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web com…
CVE-2024-21888 8.8 High Ivanti ICS A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev…
CVE-2024-22024 8.3 High Ivanti ICS An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate…
CVE-2023-46805 8.2 High Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability …
CVE-2024-21893 8.2 High Ivanti Connect Secure, Policy Secure, and Neurons Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.