CVE-2 Explained — What You Need

Unpacking CVE-2
This analysis focuses on the critical vulnerabilities impacting Ivanti Connect Secure and Policy Secure Gateways, specifically CVE-2023-46805 and CVE-2024-21887. These flaws, when chained, allow unauthenticated remote code execution. CVE-2023-46805, an authentication bypass, carries a CVSSv3.1 score of 8.2 (High). CVE-2024-21887, a command injection vulnerability, has a CVSSv3.1 score of 9.1 (Critical). These vulnerabilities affect Ivanti Connect Secure versions 9.x, 22.x, and Ivanti Policy Secure versions 9.x, 22.x. Compromised systems risk full control by attackers, leading to data exfiltration, network lateral movement, and persistent access.Technical Root Cause Analysis
CVE-2023-46805 stems from an improper authentication vulnerability within the web component of Ivanti Connect Secure and Policy Secure Gateways. The system fails to correctly validate certain specially crafted URI requests. Attackers can bypass authentication by sending specific HTTP requests to unauthenticated endpoints. These requests exploit how the system processes URL paths, allowing access to restricted resources without valid credentials. This bypass acts as a gateway for subsequent exploitation. CVE-2024-21887 is a command injection vulnerability found in multiple web components of the same products. This flaw allows an authenticated administrator to send specially crafted requests. These requests execute arbitrary commands on the appliance. The vulnerability arises from insufficient sanitization of user-supplied input. This input is then incorporated into system commands. This command injection is particularly dangerous when combined with the authentication bypass, as it enables an unauthenticated attacker to achieve remote code execution.Exploitation Mechanics
Exploitation of these vulnerabilities begins with CVE-2023-46805. An attacker sends an HTTP GET request to a specific endpoint, such as `/api/v1/license/keys-status/`. The request includes a manipulated path segment. This segment bypasses the authentication mechanism. For example, appending `/../` or similar directory traversal sequences within the URL structure allows unauthenticated access. Once authentication is bypassed, the attacker can leverage CVE-2024-21887. They send a POST request to an authenticated endpoint, typically within the `/api/v1/system/configuration/` path. This request contains malicious commands embedded within a parameter that the system executes. The command injection often targets shell commands. Attackers encode these commands within XML or JSON payloads. The system processes these payloads without proper validation, leading to command execution. An attacker could, for instance, inject commands to establish a reverse shell. They could also modify system files for persistence. This two-stage attack chain is critical.
# Example (conceptual, non-weaponized) HTTP request for CVE-2023-46805 bypass
GET /api/v1/license/keys-status/../endpoint/ HTTP/1.1
Host: vulnerable-ivanti.com
User-Agent: Mozilla/5.0
# Example (conceptual, non-weaponized) HTTP request for CVE-2024-21887 command injection
POST /api/v1/system/configuration/ HTTP/1.1
Host: vulnerable-ivanti.com
Content-Type: application/xml
Cookie: DSID=...;
<system-config>
<command>id > /tmp/output.txt</command>
</system-config>
Detection: How to Check if You're Affected
Organizations must identify vulnerable Ivanti Connect Secure and Policy Secure Gateways. Start by checking the installed version numbers. Any version before the patched releases is vulnerable. Refer to the official Ivanti Security Advisory for the specific affected versions. Review your appliance logs for indicators of compromise (IOCs). Look for unusual requests to `/api/v1/license/keys-status/` or other administrative endpoints from unauthenticated sources. Monitor for unexpected process execution or file modifications on the appliance. Specific IOCs, including IP addresses and file hashes, are often released by threat intelligence providers and government agencies like CISA. Use automated scanning tools to assess your external attack surface. A free website vulnerability scanner can identify Ivanti installations. It may detect known signatures of these vulnerabilities. A free port scanner can confirm if the administrative interfaces are exposed to the internet. This increases the risk. The technology stack detector can help identify if your public-facing systems run Ivanti products. Secably offers monitoring solutions that can help detect suspicious activity. These include checks for unusual HTTP requests. Our paid monitoring plans start at $19/month. A free tier provides instant tools without signup. For broader internet-wide reconnaissance and exposed service detection, consider using Zondex. They provide insights into your external footprint.Remediation Steps
Immediate action is necessary to mitigate these vulnerabilities. The primary remediation is to apply the vendor-provided patches. Ivanti released specific patch versions addressing both CVE-2023-46805 and CVE-2024-21887. These include versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.6R1.3 for Connect Secure. Ensure you apply the correct patch for your specific product and version. If immediate patching is not feasible, implement temporary workarounds. Ivanti provided an XML file that restricts access to vulnerable endpoints through the `file-access.cgi` component. This XML file must be imported via the administrator console. This workaround helps prevent the authentication bypass. However, it does not fully address the command injection if an attacker can still gain authenticated access through other means. The official Ivanti advisory details this mitigation. Beyond patching, implement network segmentation. Isolate Ivanti appliances from sensitive internal networks. Restrict management interface access to trusted IP addresses only. Implement multi-factor authentication for all administrative access. Regularly review audit logs for suspicious activity. Consider deploying an Intrusion Prevention System (IPS) with signatures for these CVEs. This can block known attack patterns. For a deeper understanding of exploited systems, read Unpacking an Exploited System Technical Deep Dive.Timeline of Disclosure
The vulnerabilities comprising Unpacking CVE-2 were initially discovered and reported by threat intelligence firm Volexity. They observed in-the-wild exploitation beginning in early December 2023. Volexity publicly disclosed their findings on January 10, 2024. Ivanti acknowledged the vulnerabilities and released an initial advisory on January 10, 2024. This advisory detailed CVE-2023-46805 and CVE-2024-21887. It also provided mitigation steps. Subsequently, CISA issued an alert on January 19, 2024, warning federal agencies about active exploitation. Ivanti released patches for the vulnerabilities in a staggered manner throughout January and February 2024. The situation evolved rapidly, with continuous updates from Ivanti and security researchers on new exploitation methods and indicators. Organizations need to stay informed through official vendor advisories and security bulletins.Check your site for vulnerabilities
Run a free security scan — no signup, results in seconds.