Unpacking an Exploited System Technical Deep Dive

Secably Research
Sep 29, 2026
7 min read
Vulnerability Research
Deep Dive Exploited Into Vulnerability
Unpacking an Exploited System Technical Deep Dive
Unpacking an Exploited System Technical Deep Dive

Deep Dive into Exploited Ivanti Vulnerabilities

Threat actors actively exploited two critical zero-day vulnerabilities in Ivanti Connect Secure (ICS) and Ivanti Policy Secure gateways. These vulnerabilities, CVE-2023-46805 and CVE-2024-21887, were chained together to achieve unauthenticated remote code execution (RCE) on affected appliances. This Deep Dive into Exploited vulnerabilities highlights the severe impact on network edge devices.

What the Vulnerability Is and Its Impact

CVE-2023-46805 is an authentication bypass vulnerability within the web component of Ivanti Connect Secure and Policy Secure. It allows a remote attacker to access restricted resources by bypassing control checks.

This vulnerability carries a CVSS 3.1 score of 8.2 (High severity).

CVE-2024-21887 is a command injection vulnerability in the web components of Ivanti Connect Secure and Policy Secure. It allows an authenticated administrator to execute arbitrary commands by sending specially crafted requests.

This vulnerability has a CVSS 3.1 score of 9.1 (Critical severity).

When chained, CVE-2023-46805 bypasses authentication, enabling unauthenticated execution of CVE-2024-21887. This combination grants threat actors arbitrary command execution with elevated privileges on the system without needing credentials.

All supported versions of Ivanti Connect Secure (9.x and 22.x) and Ivanti Policy Secure are affected.

Ivanti Neurons for ZTA gateways are not exploitable in production, but generated gateways left unconnected to a ZTA controller pose a risk.

Technical Root Cause Analysis

CVE-2023-46805, the authentication bypass, stems from improper authentication (CWE-287) in the web component. Attackers can manipulate specific URLs or HTTP request parameters to circumvent authentication checks. This allows access to internal APIs and resources typically protected.

The flaw likely involves an issue where URL parsing or routing logic fails to correctly enforce access controls for certain endpoints. An attacker can construct a URL that appears legitimate but, when processed by the application, bypasses the authentication gateway. For example, some reports suggest path traversal techniques within the URL structure allowed access to restricted directories.

CVE-2024-21887, the command injection, exists in multiple web components. It allows an authenticated administrator to inject and execute arbitrary commands. The vulnerability likely arises from insufficient sanitization of user-supplied input before it is passed to a system command or executed by a server-side script.

Specifically, the vulnerability resides in the command execution flow within the web components. An attacker can inject malicious commands via specially crafted requests that the appliance executes without proper validation. This is a classic command injection scenario (CWE-77 or CWE-78), where a web application directly incorporates user input into a command executed by the underlying operating system.

Exploitation Mechanics

Exploitation of these vulnerabilities typically involves a two-step process. First, the threat actor exploits CVE-2023-46805 to gain unauthenticated access to restricted administrative interfaces. This initial bypass often targets specific API endpoints.

An example of the authentication bypass in CVE-2023-46805 might involve a GET request to an endpoint like /api/v1/totp/user-backup-code/../../system/system-information. A successful 200 OK response indicates the system is vulnerable, returning system information without authentication.

GET /api/v1/totp/user-backup-code/../../system/system-information HTTP/1.1
Host: [Ivanti_Connect_Secure_IP]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36

Once unauthenticated access is achieved, the attacker then leverages CVE-2024-21887 to inject and execute commands. This command injection often occurs via a POST request to a different API endpoint, such as /api/v1/totp/user-backup-code/../../system/maintenance/archiving/cloud-server-test-connection.

The malicious command is typically embedded within a parameter of the POST request, which the vulnerable web component processes and executes on the underlying system. This allows for arbitrary command execution, providing full control over the appliance.

POST /api/v1/totp/user-backup-code/../../system/maintenance/archiving/cloud-server-test-connection HTTP/1.1
Host: [Ivanti_Connect_Secure_IP]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Content-Length: [length]

cloud=';<COMMAND_TO_EXECUTE>&

Attackers used this chain to exfiltrate configuration data, modify files, and establish reverse tunnels from compromised Ivanti Connect Secure VPN appliances.

Detection: How to Check if You're Affected

Organizations must use Ivanti's External Integrity Checker Tool (ICT) to detect potential compromises. This tool scans the file system for modified or new files, comparing them against known good baselines.

Ivanti released an updated External ICT on April 3, 2024. This version provides a decrypted snapshot of the appliance for customer review. The tool should be run after applying the latest patches to avoid false positives.

The ICT runs via the administrator console under Maintenance >> Upgrade/Downgrade >> Install Service Package. It performs a scan and may reboot the appliance.

Administrators can also find an in-built Integrity Checker Tool (ICT) in versions 9.1R12 and later. This tool can perform periodic or scheduled scans without downtime, logging new or modified system files in the Scan UI and Event Logs.

Look for specific event log IDs like `SYS32039` (Integrity Checker Failed: Detection new files!) or `SYS32040` (Integrity Checker Failed: Detected mismatched files!). These indicate a potential compromise.

However, CISA and other security researchers found that Ivanti's internal and previous external ICT versions could be deceived by sophisticated threat actors. This means the tools might fail to detect compromise.

Consider using an external vulnerability scanner to identify publicly exposed Ivanti Connect Secure instances. Secably offers a free website vulnerability scanner and a free port scanner to help identify internet-facing services and potential vulnerabilities. These tools provide an initial assessment of your external attack surface.

For more advanced attack surface management and continuous monitoring, Secably offers paid monitoring plans starting at $19/month. These services can track exposed Ivanti instances and alert on changes. Similarly, external scanning platforms like Zondex can help identify internet-wide exposure of Ivanti devices.

Organizations should review logs for unusual activity, especially POST requests to the mentioned API endpoints, even if the ICT shows a clean state. Pay attention to the HTTP status code 200 OK for these requests, which may indicate successful exploitation.

Remediation Steps

Immediate patching is the most critical step. Ivanti released patches for all supported versions of Connect Secure and Policy Secure. These patches supersede previous mitigations.

Ivanti released patches in a staggered schedule, starting the week of January 22, 2024, and continuing through February 19, 2024.

Apply the latest security updates available from Ivanti. For Ivanti Connect Secure, this includes versions 9.1R14.5, 9.1R15.3, 9.1R16.3, 9.1R17.3, 9.1R18.4, 22.1R6.1, 22.2R3, 22.2R4.1, 22.3R1.1, 22.4R1.1, 22.4R2.3, 22.5R1.2, 22.5R2.3, and 22.6R2.2.

If applying patches immediately is not possible, Ivanti provided mitigation XML files as an interim measure. However, these mitigations could impact functionality like SAML authentication.

For potentially compromised systems, a factory reset is recommended before applying patches to ensure a clean state. However, this action deletes forensic evidence. If forensic analysis is needed, capture a snapshot of the ICT results before resetting.

After applying patches, run the updated External Integrity Checker Tool to verify the system's integrity.

Implement multi-factor authentication (MFA) on all Ivanti Connect Secure administrative interfaces. This adds a layer of security, even if an authentication bypass occurs.

Restrict network access to Ivanti Connect Secure devices. Place them behind a firewall and limit access only to necessary IP ranges and ports. Use a strong firewall configuration.

Continuously monitor Ivanti appliances for suspicious activity, including unexpected outbound connections or unusual process execution. Regularly review event logs for integrity check failures.

Consider migrating to Ivanti Neurons for ZTA for improved security architecture.

Timeline of Disclosure

  • December 2023: Initial targeted exploitation of CVE-2023-46805 and CVE-2024-21887 began, observed by Volexity and Mandiant.
  • January 10, 2024: Ivanti publicly disclosed CVE-2023-46805 and CVE-2024-21887. They also provided initial mitigation steps for customers.
  • January 11, 2024: Broader exploitation began, likely related to pre-notification activity. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog.
  • January 16, 2024: Public Proof of Concept (PoC) code for the vulnerabilities was released by third parties. Intense scanning for the vulnerability also commenced.
  • January 19, 2024: CISA issued Emergency Directive (ED) 24-01, requiring federal agencies to mitigate the vulnerabilities.
  • January 22, 2024: Ivanti started releasing initial patches, with a staggered schedule planned through February 19, 2024.
  • January 31, 2024: Ivanti released an advisory about new critical vulnerabilities (CVE-2024-21888 and CVE-2024-21893) and updated patches.
  • February 8, 2024: Ivanti released an advisory for CVE-2024-22024, another authentication bypass, and new security updates replacing previous ones.
  • February 29, 2024: CISA and partners released a joint Cybersecurity Advisory, confirming threat actors could deceive Ivanti's ICT and achieve root-level persistence even after factory resets.
  • April 3, 2024: An updated External Integrity Checker Tool was released by Ivanti.

Check your site for vulnerabilities

Run a free security scan — no signup, results in seconds.

Related Posts

Stronger security starts with visibility.

Scan your website for vulnerabilities and get actionable insights.