Active exploitation of Ivanti Connect Secure / Policy Secure vulnerabilities (CVE-2023-46805, CVE-2024-21887)
Ivanti and CISA warned of active exploitation of vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS), urging organizations to apply mitigations and updates. CISA issued emergency directives and alerts for federal agencies and provided guidance for broader organizations, reflecting the severity and active exploitation status. The incident illustrates the rapid operational and financial risk created when widely deployed VPN/access gateways are exploited at scale.
First reported January 10, 2024Vuln Exploitationhigh overall confidence
T1190: CISA and Ivanti described active exploitation of internet-facing VPN/access gateway vulnerabilities for initial access.
Mitigations
Now
Apply Ivanti security updates and follow vendor mitigation guidance (including integrity checks)Removes or reduces the exploited weakness and helps identify compromised appliances.
Soon
Isolate appliances and restrict administrative access (management interfaces, MFA, allowlisted IPs)Reduces exposure of high-value gateway systems and limits attacker opportunities.
Later
Rotate credentials and tokens used by/through the gateway (VPN creds, API tokens, service accounts)Mitigates risk of stolen credentials being reused after appliance compromise.
Detection ideas
Detect suspicious requests and exploitation patterns in appliance and web logs
Search for IOCs and unusual request paths/parameters identified by vendor and CISA; alert on repeated hits to known vulnerable endpoints.
Data sources: Ivanti appliance logs, Web server access logs, WAF logs
Detect post-exploitation artifacts and unexpected administrative changes
Alert on new admin accounts, unexpected config changes, unusual outbound connections from the appliance, or file changes indicative of web shell implantation.
Data sources: Appliance audit logs, EDR telemetry on adjacent hosts, SIEM