← Back to advisories & guidance
January 19, 2024
CISA
Alert
Summary
ED 24-01 directs all Federal Civilian Executive Branch (FCEB) agencies running Ivanti Connect Secure and Ivanti Policy Secure to: Report indications of compromise to CISA. Remove compromised products from agency networks and follow the ED’s comprehensive instructions for restoring and bringing the products back into service. Provide CISA with a report that includes: A complete inventory of all instances of Ivanti Connect Secure and Ivanti Policy Secure products on agency networks. A complete inventory of all instances of Ivanti Connect Secure and Ivanti Policy Secure products on agency networks. Although this directive is only for FCEB agencies, CISA strongly encourages all organizations to address the vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure. For additional details, see CISA’s Alert, Ivanti Releases Security Update for Connect Secure and Policy Secure Gateways , which CISA will update with further mitigations and patches as these become available.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.