Ivanti has warned of two new vulnerabilities affecting Connect Secure, Policy Secure, and ZTA gateways.

One of them is a zero-day and has already been used in attacks. Tracked as CVE-2024-21893 , it is a server-side request forgery bug in the SAML component of gateways, which allows attackers to bypass authentication and gain access to restricted resources on vulnerable devices.
The second vulnerability, CVE-2024-21888, is located in the web component of gateways and allows attackers to gain more privileges and act as administrators.
See also: Vulnerability in glibc allows root access on Linux distributions
The discovery of the two new vulnerabilities was made as part of a research that identified other bugs a few days ago.
“The new vulnerabilities affect all supported versions – Version 9.x and 22.x,” the company said today.
As mentioned earlier, the CVE-2024-21893 vulnerability has been used in some attacks, but research to date has not shown the CVE-2024-21888 vulnerability being used against clients.
Ivanti has released security to address both vulnerabilities for some affected ZTA and Connect Secure versions and provides mitigation instructions for devices that cannot yet receive the update.
See also: Chinese hackers exploit zero-day vulnerabilities in VPNs
The company recommends that users immediately take the necessary measures to protect themselves.
Additionally, Ivanti released updates for two other zero-day vulnerabilities that were disclosed in early January – an authentication bypass (CVE-2023-46805) and a command injection (CVE-2024-21887). The two have been used in large-scale malware deployment attacks.

What will happen if the information is not implemented and protective measures are not taken?
The first and most immediate consequence is the possibility of exploiting the vulnerabilities by malicious users. This can lead to a loss of control over the system, with attackers being able to gain privileges and execute code on vulnerable devices.
See also: Outlook: Vulnerability could expose NTLM passwords
Second, failure to patch vulnerabilities can lead to data leakage. This can include sensitive information, such as personal data, financial details, or company secrets, which can be used for fraud or phishing attacks.
Finally, the attack can cause operations system, which can lead to loss of productivity and additional costs to restore operations.
Source: www.bleepingcomputer.com
