{"id":4646,"date":"2024-02-16T11:37:54","date_gmt":"2024-02-16T18:37:54","guid":{"rendered":"https:\/\/zed.inguardians.com\/?p=4646"},"modified":"2024-02-16T11:37:54","modified_gmt":"2024-02-16T18:37:54","slug":"a-fifth-vulnerability-found-in-ivanti-vpns","status":"publish","type":"post","link":"https:\/\/zed.inguardians.com\/blog\/a-fifth-vulnerability-found-in-ivanti-vpns\/","title":{"rendered":"A Fifth Vulnerability Found in Ivanti VPNs"},"content":{"rendered":"

Issue<\/b><\/p>\n

On Friday, February 9th, Ivanti disclosed<\/span>[1]<\/span> another vulnerability found in its Ivanti Connect Secure (formerly Pulse Secure) and Ivanti Policy Secure VPN products. Named CVE-2024-22024, this vulnerability permits a bad actor to access restricted product resources without authentication.. By exploiting this vulnerability and one other in concert, a bad actor could fully compromise the VPN appliance. The actor could steal passwords and use the appliance as a beachhead to attack the rest of an Ivanti customer\u2019s network.<\/span><\/p>\n

This is the fifth recently disclosed vulnerability in the Ivanti Connect Secure and Policy Secure products. Espionage operations linked to China initially led to exploiting these vulnerabilities, according to Mandiant (with medium confidence). As proof of concept exploits have become available, including a Metasploit module,<\/span>[2]<\/span> the breadth of perpetrators has grown. The US Cybersecurity Infrastructure and Security Agency (CISA) found the risks here strong enough to initially order all federal agencies to apply mitigations and patches, but then to replace that with an order to disconnect, wipe, and update the appliances. CISA also directed agencies to assume all domain accounts associated with the products were compromised. The wider information security community shares CISA\u2019s concerns.\u00a0<\/span><\/p>\n

Impact<\/b><\/p>\n

Many organizations running the affected Ivanti products have already been breached, with two specific goals seeing the most exposure:<\/span><\/p>\n