Ivanti’s Persistent Pain: Your VPN Is Still a Hacker’s Playground!
Alright, folks, let’s cut to the chase: Ivanti Connect Secure and Policy Secure gateways are still a massive headache for security teams worldwide. Despite multiple patches, these devices continue to be a prime target for state-sponsored and financially motivated threat actors, leading to widespread exploitation and network breaches.[1]
This isn’t just old news; it’s a persistent, evolving threat. Multiple critical vulnerabilities, including authentication bypass (CVE-2023-46805), command injection (CVE-2024-21887), server-side request forgery (CVE-2024-21888), and a privilege escalation flaw (CVE-2024-21893), have been actively exploited in the wild. More recently, another critical vulnerability, CVE-2024-22024, an XML external entity (XXE) vulnerability, was discovered and exploited, allowing unauthenticated attackers to access restricted resources.[2] These flaws provide a juicy entry point, often leading to full compromise of the appliance and, subsequently, the internal network. Various APT groups and ransomware gangs have been quick to weaponize these exploits, often deploying web shells and backdoors for persistent access.[3]</



