SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • January 11, 2024
  • Rss Fetcher

IT administrators with Ivanti’s  Connect Secure/Pulse Secure VPNs and Policy Secure gateways are urged to install mitigations immediately.
The mitigations are to temporarily deal with two vulnerabilities (CVE-2023-46805, an authentication bypass and CVE-2024-21887, a command injection) that impact all supported versions of these products.
If they are chained together, “exploitation does not require authentication and enables a threat actor to craft malicious requests and execute arbitrary commands on the system,” the company said.
“It is critical that you immediately take action to ensure you are fully protected,” the company said in an advisory.
Patches will be released in a staggered schedule, with the first version targeted to be available to customers the week of Jan. 22, with the final version targeted to be available the week of Feb. 19. Until then, the mitigations will have to do.
The vulnerabilities were discovered by researchers at Volexity, who in December detected suspicious lateral movement on the network of one of its network security monitoring service customers. An attacker was placing webshells on the customer’s internal and external-facing web servers. Investigating further, Veloxity found that logs on the customer’s Ivanti Connect Secure VPN had been wiped and logging had been disabled. It then discovered two different zero-day exploits which were being chained together to achieve unauthenticated remote code execution.
“When combined, these two vulnerabilities make it trivial for attackers to run commands on the system,” Volexity says in its report. “In this particular incident, the attacker leveraged these exploits to steal configuration data, modify existing files, download remote files, and reverse tunnel from the … VPN appliance.”
Among other things, the attacker modified legitimate Connect Secure components and made changes to the system to evade the the VPN’s Integrity Checker Tool.
“As organizations continue to improve and harden their defense, attackers are continually looking for ways to bypass them,” the Volexity report says. “Internet-accessible systems, especially critical devices like VPN appliances and firewalls, have once again become a favorite target of attackers. These systems often sit on critical parts of the network, cannot run traditional security software, and typically sit at the perfect place for an attacker to operate.
“Organizations need to make sure they have a strategy in place to be able to monitor activity from these devices and quickly respond if something unexpected occurs.”The post Warning issued to admins of Ivanti Connect Secure and Policy Secure gateways first appeared on IT World Canada.

Previous Post
Next Post

Recent Posts

  • Google reportedly plans to cut ties with Scale AI
  • How to delete your 23andMe data
  • Waymo limits service ahead of today’s ‘No Kings’ protests
  • Week in Review: WWDC 2025 recap
  • The App Store’s new AI-generated tags are live in the beta

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • June 2025
  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.