← Ivanti

2024 Ivanti Connect Secure / Policy Secure — chained auth-bypass + RCE CVEs; global mass exploitation

2024 Unknown records affected Share on X

Data compromised

VPN-session credentials, appliance configs, and authentication stores on compromised customer devices

Technical writeup

Beginning in late 2023 and escalating through January–February 2024, multiple nation-state and crimeware groups chained zero-day and n-day flaws—including CVE-2023-46805 (authentication bypass), CVE-2024-21887 (command injection), CVE-2024-21888, CVE-2024-21893, and CVE-2024-22024—affecting supported Ivanti Connect Secure and Policy Secure VPN/concentrator appliances. CISA, Ivanti, and Unit 42 documented widespread internet-facing exploitation, credential theft, webshell persistence, and downstream lateral movement into enterprise directories. While victim counts are decentralized, the campaign represents one of the largest edge-device compromises of the period and materially exposed session credentials and secrets held on customer gateways.

Root cause

Chained remote-code and SSRF-class flaws in edge VPN appliances under active exploitation

References