Vulnerability record · CVE-2024-37404 · published 18 October 2024
CVE-2024-37404: Ivanti Connect Secure admin portal input validation flaw enables RCE
Ivanti · Connect Secure
Ivanti Connect Secure and Policy Secure contain an improper input validation flaw in the admin portal. A remote authenticated attacker can exploit it to achieve remote code execution on the appliance. Because these are edge security gateways, successful exploitation can expose the internal network.
Description
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution on an edge security appliance with a CVSS of 8.8 and very high EPSS, though it requires authenticated admin access.
What it is
Ivanti Connect Secure and Policy Secure contain an improper input validation flaw in the admin portal. A remote authenticated attacker can exploit it to achieve remote code execution on the appliance. Because these are edge security gateways, successful exploitation can expose the internal network.
Impact
An attacker with valid admin-portal credentials gains remote code execution on the appliance, allowing them to run commands, access secrets and pivot into the protected network.
Attack surface
Reached over the network through the admin portal (AV:N, AC:L, PR:L, UI:N). Authentication is required; no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.70955 (99.37th percentile), indicating a high predicted likelihood of exploitation.
What to do
- Apply the vendor patch: upgrade Connect Secure to 22.7R2.1 or 9.1R18.9, and Policy Secure to 22.7R1.1 or later.
- Restrict admin portal access to trusted management networks and disable internet-facing admin interfaces.
- Enforce strong unique credentials and MFA for all admin accounts; audit for stale or shared accounts.
- Monitor and rotate any credentials or secrets stored on or accessible from the appliance.
- Review Ivanti advisory guidance for additional hardening and compromise checks.
Detection
- Monitor admin portal logs for unexpected command execution, process spawning or web shell activity.
- Alert on anomalous admin logins, especially from new source IPs or outside maintenance windows.
- Hunt for outbound connections from the appliance to unusual destinations that could indicate post-exploitation.
- Check for unexpected files, scheduled tasks or configuration changes on the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-and-Policy-Secure-CVE-2024-37404 | PatchVendor Advisory |
Track CVE-2024-37404 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-37404), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.