Executive brief
An authentication bypass vulnerability in the web component of Ivanti Connect Secure and Policy Secure gateways allows remote attackers to access restricted resources by bypassing control checks. This vulnerability is known to be exploited in the wild, often in conjunction with CVE-2024-21887 to achieve remote code execution.
Affected products
- Ivanti Connect Secure (ICS) 9.x, 22.x
- Ivanti Policy Secure All versions
Timeline
- 2024-01-10: disclosed: Initial disclosure date
- 2024-01-10: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2024-01-12: other: NIST initial analysis and CVSS assignment