← Vulnerability feed

Vulnerability record · CVE-2024-21887 · published 12 January 2024

CVE-2024-21887: Ivanti Connect Secure and Policy Secure web component command injection

Ivanti · Connect Secure

Ivanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can send specially crafted requests to execute arbitrary commands on the appliance. Because these are edge VPN gateways, compromise gives attackers a foothold inside the network.

9.1 CVSS 3.1 Critical CISA KEV since 10 Jan 2024 Known ransomware use EPSS 100% · top 0.1% CWE-77 · Command injection
9.1CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References, 2 tagged exploit
4 Aug 2026Last modified by NVD

Description

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.1, active exploitation in CISA KEV with ransomware use, and near-maximum EPSS make this an urgent edge-device risk.

What it is

Ivanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can send specially crafted requests to execute arbitrary commands on the appliance. Because these are edge VPN gateways, compromise gives attackers a foothold inside the network.

Impact

An attacker with administrative access can execute arbitrary commands on the appliance, leading to full compromise of the gateway and potential lateral movement into internal networks.

Attack surface

Reachable over the network via the web interface (AV:N, AC:L, PR:H, UI:N). The CVSS vector requires high privileges, so authentication as an administrator is needed; no user interaction is required.

Exploitation

CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is near 1.0 (0.99999). Public exploit code is referenced (Packet Storm), and it is chained with CVE-2023-46805 authentication bypass for unauthenticated remote code execution.

What to do

  • Apply the vendor patch or mitigation per Ivanti's advisory immediately; if no fix is available, discontinue use of the product as CISA directs.
  • Isolate or restrict management and web interface access to trusted networks and administrative IPs.
  • Reset administrator credentials and review accounts for unauthorized changes after suspected exposure.
  • Monitor Ivanti advisories and CISA KEV for updated guidance and apply any follow-up patches.
  • Consider temporarily disabling or removing the appliance from the internet if it cannot be patched.

Detection

  • Inspect web server and appliance logs for crafted requests targeting web components, especially unusual command-like parameters.
  • Hunt for unexpected child processes or command execution spawned by the web service on the appliance.
  • Monitor for outbound connections or file changes on the appliance consistent with post-exploitation activity.
  • Correlate with CVE-2023-46805 authentication bypass attempts in logs to detect chained exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-21887 to the Known Exploited Vulnerabilities catalog on 10 January 2024 as "Ivanti Connect Secure and Policy Secure Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 22 January 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21887 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-21887), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.