Vulnerability record · CVE-2024-21887 · published 12 January 2024
CVE-2024-21887: Ivanti Connect Secure and Policy Secure web component command injection
Ivanti · Connect Secure
Ivanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can send specially crafted requests to execute arbitrary commands on the appliance. Because these are edge VPN gateways, compromise gives attackers a foothold inside the network.
Description
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.1, active exploitation in CISA KEV with ransomware use, and near-maximum EPSS make this an urgent edge-device risk.
What it is
Ivanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can send specially crafted requests to execute arbitrary commands on the appliance. Because these are edge VPN gateways, compromise gives attackers a foothold inside the network.
Impact
An attacker with administrative access can execute arbitrary commands on the appliance, leading to full compromise of the gateway and potential lateral movement into internal networks.
Attack surface
Reachable over the network via the web interface (AV:N, AC:L, PR:H, UI:N). The CVSS vector requires high privileges, so authentication as an administrator is needed; no user interaction is required.
Exploitation
CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is near 1.0 (0.99999). Public exploit code is referenced (Packet Storm), and it is chained with CVE-2023-46805 authentication bypass for unauthenticated remote code execution.
What to do
- Apply the vendor patch or mitigation per Ivanti's advisory immediately; if no fix is available, discontinue use of the product as CISA directs.
- Isolate or restrict management and web interface access to trusted networks and administrative IPs.
- Reset administrator credentials and review accounts for unauthorized changes after suspected exposure.
- Monitor Ivanti advisories and CISA KEV for updated guidance and apply any follow-up patches.
- Consider temporarily disabling or removing the appliance from the internet if it cannot be patched.
Detection
- Inspect web server and appliance logs for crafted requests targeting web components, especially unusual command-like parameters.
- Hunt for unexpected child processes or command execution spawned by the web service on the appliance.
- Monitor for outbound connections or file changes on the appliance consistent with post-exploitation activity.
- Correlate with CVE-2023-46805 authentication bypass attempts in logs to detect chained exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-21887 to the Known Exploited Vulnerabilities catalog on 10 January 2024 as "Ivanti Connect Secure and Policy Secure Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 22 January 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Con | Vendor Advisory |
| http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Con | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21887 | US Government Resource |
Track CVE-2024-21887 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-21887), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.