CVE- Explained — What It Is, How to Spot

Secably Research
Oct 11, 2026
7 min read
Vulnerability Research
Cve Dive Into Vulnerability
CVE- Explained — What It Is, How to Spot
CVE- Explained — What It Is, How to Spot

Deep Dive into CVE-2023-46805 and CVE-2024-21887

This Deep Dive into CVE-2023-46805 and CVE-2024-21887 examines critical vulnerabilities in Ivanti Connect Secure (ICS) and Policy Secure gateways. Attackers actively exploited these flaws as zero-days, leading to widespread compromise of vulnerable appliances. The initial vulnerability, CVE-2023-46805, is an authentication bypass, while CVE-2024-21887 is a command injection. Chaining these two vulnerabilities allows unauthenticated attackers to execute arbitrary commands remotely on affected systems.

What the Vulnerability Is and Its Impact

CVE-2023-46805 is an authentication bypass vulnerability. It affects Ivanti Connect Secure (ICS) versions 9.x and 22.x, and Ivanti Policy Secure versions 9.x and 22.x. This flaw allows an unauthenticated attacker to access restricted resources by bypassing authentication checks. The CVSS v3.1 score for CVE-2023-46805 is 8.2 (High). CVE-2024-21887 is a post-authentication command injection vulnerability. It impacts the same Ivanti Connect Secure and Policy Secure versions. An authenticated attacker can inject arbitrary commands, achieving remote code execution. When chained with CVE-2023-46805, this becomes a critical unauthenticated remote code execution vector. The CVSS v3.1 score for CVE-2024-21887 is 9.1 (Critical). Affected versions include Ivanti Connect Secure and Ivanti Policy Secure gateways prior to 9.1R14.2, 9.1R17.1, 9.1R18.3, 22.4R1.1, 22.5R1.1, and 22.6R1.1. Ivanti's advisory KB44774 details the specific versions and corresponding patches. Organizations using these products faced significant risk from active exploitation campaigns.

Technical Root Cause Analysis

The root cause for CVE-2023-46805 lies in improper input validation within the Ivanti Connect Secure web component. The system's authentication handler, specifically the `web.authenticate()` function, failed to correctly process certain URI patterns. Ivanti appliances use Apache HTTP Server as a front-end, which proxies requests to a backend application server. The vulnerability arises because the authentication filter, likely implemented in the application logic, processes the request path before Apache performs full URI normalization. Attackers exploited this discrepancy. They crafted URLs containing encoded directory traversal sequences, such as `../` or `..%2f`, within the `/dana-na/` path. For example, a request to `/dana-na/../dana-admin/filewrite/` could bypass the authentication check for the `/dana-na/` prefix. The authentication module would see the `dana-na` part and might incorrectly categorize it as an unauthenticated path or simply fail to apply the necessary checks. Subsequently, Apache or the backend application would normalize the URI, resolving it to a protected administrative endpoint. This allowed unauthenticated access to sensitive administrative APIs. CVE-2024-21887, the command injection, exists in multiple web components accessible after authentication. This vulnerability stems from insufficient sanitization of user-supplied input before its inclusion in shell commands. An authenticated administrator could submit specially crafted input to various administrative endpoints. The application then executed this input directly within system commands without proper escaping or validation. One specific instance of CVE-2024-21887 involved parameters related to file operations or system diagnostics. For example, an administrative function designed to archive logs might construct a shell command using a user-provided filename. If the filename parameter was not adequately sanitized, an attacker could inject shell metacharacters (e.g., `;`, `|`, `&`) to append arbitrary commands. The system would then execute these injected commands with the privileges of the underlying web service.

Exploitation Mechanics

Exploiting CVE-2023-46805 requires crafting a specific HTTP GET request. An attacker sends a request to a vulnerable Ivanti appliance with a malformed URI. This URI bypasses the `web.authenticate()` function. The goal is to reach an administrative endpoint without providing valid credentials. An example of a bypass attempt might look like this:
GET /dana-na/../dana-admin/setlicense.cgi HTTP/1.1
Host: vulnerable-ivanti.com
User-Agent: Mozilla/5.0
Connection: close
This request attempts to access `setlicense.cgi`, an administrative script, by misdirecting the authentication handler with `../`. Successful exploitation grants access to administrative APIs. This access allows the attacker to perform actions typically reserved for authenticated users. Once authentication is bypassed using CVE-2023-46805, an attacker can then chain CVE-2024-21887. This involves sending a POST request to a vulnerable administrative endpoint with injected commands. A common target for the command injection was the `/api/v1/system/maintenance/` endpoint, or similar paths handling system configurations or file operations. Consider an attacker who has bypassed authentication. They might send a request similar to this, targeting a function that processes a `command` parameter:
POST /dana-na/../dana-admin/diag/diag.cgi HTTP/1.1
Host: vulnerable-ivanti.com
Content-Type: application/x-www-form-urlencoded
Content-Length: [LENGTH]

command=ping; id > /tmp/pwned.txt
This example demonstrates injecting `id > /tmp/pwned.txt` after a legitimate `ping` command. The server executes `ping`, then executes `id` and redirects its output to `/tmp/pwned.txt`. This confirms successful command injection and remote code execution. Attackers commonly used this chain to deploy web shells, establish persistence, and move laterally within compromised networks.

Detection: How to Check if You're Affected

Organizations must identify if their Ivanti Connect Secure or Policy Secure gateways are vulnerable. Start by identifying all public-facing Ivanti appliances. A Zondex scan can help identify internet-exposed Ivanti instances. You can also use a technology stack detector to confirm Ivanti products. Check the version numbers of your Ivanti Connect Secure and Policy Secure installations. Compare these against the patched versions listed in Ivanti's Security Advisory KB44774. Any appliance running a version prior to 9.1R14.2, 9.1R17.1, 9.1R18.3, 22.4R1.1, 22.5R1.1, or 22.6R1.1 is vulnerable. Look for indicators of compromise (IoCs). Ivanti provided a public integrity checker tool. Run this tool to detect unauthorized modifications to the system. Additionally, review system logs for unusual activity, such as unauthorized access attempts to administrative URLs or unexpected command executions. Specifically, search for HTTP requests containing `../` or `..%2f` directed at `/dana-na/` paths from unauthenticated sources. Monitor network traffic for outbound connections from your Ivanti appliance to unusual external IP addresses or domains. Attackers often establish command and control (C2) channels after gaining initial access. A free port scanner can help identify unexpected open ports on your Ivanti appliance. Secably's free website vulnerability scanner can also help identify publicly known vulnerabilities and misconfigurations on the web interface, though specific zero-day detection requires more specialized tools.

Remediation Steps

Immediate remediation involves patching all affected Ivanti Connect Secure and Policy Secure gateways. Apply the vendor-provided hotfixes or upgrade to the recommended secure versions as detailed in Ivanti's Security Advisory KB44774. Ivanti released specific patch versions:
  • 9.1R14.2
  • 9.1R17.1
  • 9.1R18.3
  • 22.4R1.1
  • 22.5R1.1
  • 22.6R1.1
Do not simply apply the hotfix without a full system integrity check. Active exploitation may have left backdoors or persistent access. Consult Ivanti's guidance for a comprehensive remediation process, which includes running the Ivanti Integrity Checker tool. After patching, revoke all existing session tokens and reset credentials for administrative accounts. Attackers may have stolen these during exploitation. Force all users to re-authenticate. Review and harden firewall rules to restrict access to the Ivanti appliance's administrative interfaces to only trusted IP addresses. Implement multi-factor authentication (MFA) for all administrative access. Consider isolating the Ivanti appliance within your network as an additional security measure. This limits potential lateral movement if a compromise occurs. Regularly review logs for suspicious activity. Implement robust endpoint detection and response (EDR) solutions on any internal systems potentially accessed from the Ivanti appliance. For more general guidance on understanding and addressing vulnerabilities, refer to our blog post CVEs Explained — How to Understand Them and What.

Timeline of Disclosure

The timeline for the Deep Dive into CVE-2023-46805 and CVE-2024-21887 involved rapid detection and response due to active exploitation.
  1. December 2023: Ivanti became aware of active, targeted exploitation of these vulnerabilities as zero-days.
  2. January 10, 2024: Ivanti publicly disclosed CVE-2023-46805 and CVE-2024-21887. They released initial mitigation guidance and a community forum post.
  3. January 11, 2024: The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive ED-24-01, urging federal agencies to disconnect Ivanti Connect Secure and Policy Secure products due to active exploitation. CISA also released Alert AA24-011A, detailing the vulnerabilities and IoCs.
  4. January 23, 2024: Ivanti began releasing patches for some affected versions.
  5. February 2024: Ivanti released additional patches to cover all affected versions.
  6. October 11, 2026: Ongoing monitoring and patching remain critical for organizations.
This rapid disclosure timeline highlights the severe nature and active threat these vulnerabilities posed to organizations globally. Continuous vigilance and adherence to vendor advisories are essential for maintaining security posture.

Check your site for vulnerabilities

Run a free security scan — no signup, results in seconds.

Related Posts

Stronger security starts with visibility.

Scan your website for vulnerabilities and get actionable insights.