Full Report
Detect and mitigate CVE-2023-46805, CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893, critical vulnerabilities in Ivanti VPN products. Organizations should patch urgently, and government agencies are instructed to isolate Ivanti VPN instances.
Analysis Summary
# Vulnerability: Ivanti Connect/Policy Secure Authentication Bypass via SAML (CVE-2024-22024)
## CVE Details
- CVE ID: CVE-2024-22024
- CVSS Score: [Score not explicitly listed, but described as 'high severity']
- CWE: (Not explicitly listed, but related to SAML Authentication Bypass)
## Affected Systems
- Products: Ivanti Connect Secure, Ivanti Policy Secure, ZTA gateways
- Versions:
- Connect Secure: `9.x`, `22.x` (Specific fixed versions provided for patching)
- Policy Secure: `9.x`, `22.x` (Specific fixed versions provided for patching)
- Configurations: Flaw exists within the SAML component.
## Vulnerability Description
CVE-2024-22024 is an authentication bypass vulnerability residing in the SAML component of affected Ivanti products. Successful exploitation allows an unauthenticated attacker to access certain restricted resources on the gateway devices.
## Exploitation
- Status: **Exploited in the wild** (Reported February 9, 2024)
- Complexity: Not explicitly rated, but likely low given the authentication bypass nature.
- Attack Vector: Network
## Impact
(Impact levels for CVE-2024-22024 are not explicitly detailed beyond enabling access to restricted resources. Assuming high impact due to unauthenticated access.)
- Confidentiality: High (Access to restricted resources)
- Integrity: Unknown
- Availability: Unknown
## Remediation
### Patches
Ivanti released patches on February 8, 2024. Customers are urged to patch urgently.
- **Connect Secure Fixed Versions:** `9.1R14.5`, `9.1R17.3`, `9.1R18.4`, `22.4R2.3`, `22.5R1.2`, `22.5R2.3`, `22.6R2.2`
- **Ivanti Policy Secure Fixed Versions:** `9.1R17.3`, `9.1R18.4`, `22.5R1.2`
- **ZTA Gateways Fixed Versions:** `22.5R1.6`, `22.6R1.5`, `22.6R1.7`
### Workarounds
No specific workarounds for CVE-2024-22024 are explicitly detailed in the summary, but general advice regarding previously disclosed vulnerabilities included isolating products from the Internet.
## Detection
- Detection tools referenced include the **Wiz Threat Center** pre-built query/advisory for searching vulnerable instances.
## References
- Ivanti advisory (current): hxxps://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US
- Exploitation reported: hxxps://twitter.com/GossiTheDog/status/1755949758160523570
- WatchTowr Labs blog: hxxps://labs.watchtowr.com/are-we-now-part-of-ivanti/
---
***Note on Related Flaws (For Context of Urgent Mitigation):***
The advisory also references four other critical vulnerabilities disclosed earlier that require patching:
1. **CVE-2023-46805** (Authentication Bypass in Web Component)
2. **CVE-2024-21887** (Command Injection in Web Component - can lead to RCE when combined with CVE-2023-46805)
3. **CVE-2024-21888** (Privilege Escalation in Web Component)
4. **CVE-2024-21893** (SSRF in SAML component - exploited in the wild)
Patches for all four of these vulnerabilities were available as of February 1, 2024. CISA mandated federal agencies to disconnect affected products by February 2, 2024.