Ivanti VPN’s SSRF Vulnerability Gains Huge Exploit Momentum

February 6, 2024
1 min read

The recent SSRF vulnerability in Ivanti VPN products is being actively exploited by threat actors, according to the Shadowserver Foundation. The attacks target the SAML component of Ivanti Connect Secure, Policy Secure, and Neurons for ZTA, allowing attackers to access restricted resources without authentication. The exploitation attempts have originated from over 170 unique IP addresses and involve the establishment of a reverse shell. Ivanti has released initial mitigations and has now begun releasing official patches to address the vulnerability. However, threat actors have found ways to bypass the initial mitigation, leading Ivanti to release a second mitigation file.

Last week, cybersecurity firm Rapid7 released a proof-of-concept exploit that combines the SSRF flaw with a previously patched command injection flaw to achieve unauthenticated remote code execution. Additionally, security researcher Will Dormann pointed out that the Ivanti VPN appliances use out-of-date open-source components, leaving them vulnerable to further attacks.

Palo Alto Networks Unit 42 has observed 28,474 exposed instances of Ivanti Connect Secure and Policy Secure in 145 countries, with 610 compromised instances detected in 44 countries. These instances have been targeted by threat actors deploying custom web shells.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is