HomeSecurityIvanti: Massive exploitation of vulnerability by cybercriminals

Ivanti: Massive vulnerability exploitation by cybercriminals

A vulnerability in Ivanti Connect Secure and Ivanti Policy Secure, tracked as CVE-2024-21893, is being widely exploited by cybercriminals to carry out attacks.

Ivanti: Massive vulnerability exploitation by cybercriminals

Ivanti warned about the vulnerability in the SAML components of the gateway on January 31, 2024. At the time, it said that it was a zero-day with a limited exploit, targeting a small number of customers.

However, the CVE-2024-21893 exploit allows attackers to bypass authentication and gain access to restricted resources on vulnerable devices (versions 9.x and 22.x).

According to threat monitoring service Shadowserver, many cybercriminals are now using the Ivanti vulnerability (at least 170 IP addresses are trying to exploit it).

See also: Mispadu banking trojan: Exploits Windows SmartScreen vulnerability

The increased exploitation may be due to the proof-of-concept (PoC) exploit released by Rapid7 researchers on February 2, although Shadowserver had identified attackers using similar exploitation methods hours before the Rapid7 report was published.

According to ShadowServer, there are currently nearly 22,500 Ivanti Connect Secure devices exposed on the Internet, but we don't know how many of them are vulnerable to the vulnerability in question.

Ivanti vulnerability

Many vulnerabilities in Ivanti products

The disclosure of the CVE-2024-21893 vulnerability came alongside the release of security updates for two other zero-day vulnerabilities affecting the same products: CVE-2023-46805 and CVE-2024-21887, which were first reported on January 10, 2024.

Both of these vulnerabilities were exploited by the Chinese group UTA0178/UNC5221 to install webshells and backdoors on compromised devices. These infections peaked in mid-January.

See also: Mastodon: Vulnerability allows account theft

The company initially proposed some mitigations for these vulnerabilities. However, attackers were able to bypass them and even compromise the device's configuration files, leading Ivanti to postpone firmware updates to address the threat.

Due to increased exploitation of multiple vulnerabilities and the lack of security updates for some affected product versions, CISA has ordered federal agencies to disconnect all devices Connect Secure and Policy Secure VPN

Only devices that have been factory reset and upgraded to the latest firmware version can be used. Private organizations if they want to stay safe (in their case, there is no mandate).

Ivanti: Massive vulnerability exploitation by cybercriminals

How to protect yourself from Ivanti vulnerabilities

One of the most effective ways to protect yourself from vulnerability exploitation is to apply the latest security and patches (when released by Ivanti).

See also: RunC: Vulnerabilities allow attackers access

Additionally, using a robust intrusion detection software (IDS) or intrusion prevention system (IPS) can help detect and prevent zero-day exploitation attempts.

Educating users on safe internet use and recognizing phishing attacks is also crucial. Phishing are a common tactic used by attackers to exploit zero-days.

Finally, using specialized vulnerability management software can help detect and prevent zero-day attacks. This software can continuously monitor the network for signs of attacks and provide alerts when it detects something suspicious.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS