DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-10
vulnerabilitycritical

Ivanti Connect Secure & Policy Secure Command Injection

EXECUTIVE INTELLIGENCE SUMMARY

Command injection in Ivanti web component allowing authenticated administrators (or unauthenticated attackers when chained with CVE-2023-46805) to execute arbitrary commands.

Chained with an authentication bypass in the `/api/v1/totp/user-backup-code` endpoint, attackers send malicious JSON payloads to the `/api/v1/license/keys-status/` URI, appending bash shell injection parameters that execute with root privileges on the appliance.

TECHNICAL EXPLOITATION MATRIX
CVSS v4.0 SCORE
9.1 / 10.0
CRITICAL BASE SEVERITY
EPSS EXPLOIT PROBABILITY
97.4%
PERCENTILE 98.4
EXPLOITED IN THE WILD
CONFIRMED
CISA KEV CATALOG
AFFECTED SOFTWARE BUILDS
Ivanti Connect Secure (Ivanti)
AFFECTED: 9.x, 22.x
FIXED IN: 22.6R2.1
RECOMMENDED REMEDIATION & MITIGATIONS
  • [1]Apply Ivanti XML workaround mitigating REST API routing.
  • [2]Run External Integrity Checker Tool (ICT) for indicators of persistent webshells.
SOURCE CITATIONS & ATTESTATIONS (1)
CISA Emergency Directive 24-01CISA

Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities

TELEMETRY CARDID: cve-2024-21887
ENTITY TYPE
vulnerability
INDEXED TAGS
#vpn_gateway#edge_device#ivanti#cisa_kev#command_injection