8.4.24 | UPDATE
These vulnerabilities along with CVE-2024-21893, is currently exploited by Chinese state-sponsored APT groups to conduct various attacks. Among these groups are UNC5221, UNC3569, UNC5330, and UNC5337.
It is important to upgrade both Ivanti Connect Secure VPN and Ivanti Policy Secure to their latest versions. According to Ivanti a patch is available for Ivanti Connect Secure (versions 9.1R15.3, 9.1R16.3, 22.1R6.1, 22.2R4.1, 22.3R1.1 and 22.4R1.1) and Ivanti Policy Secure (versions 9.1R16.3, 22.4R1.1 and 22.6R1.1). A build is available for all supported versions.
******************************
In a recent development that demands immediate attention from the cybersecurity community, two zero-day vulnerabilities have been unearthed in Ivanti Connect Secure (ICS) and Policy Secure. The gravity of the situation is compounded by the active exploitation of these vulnerabilities by suspected China-linked nation-state actors.
The threat actors have successfully exploited these vulnerabilities in the wild, affecting less than 10 of the vendor’s customers. The attack involves chaining the two vulnerabilities to achieve unauthenticated command execution on the ICS device. If CVE-2024-21887 is used with CVE-2023-46805, exploitation does not require authentication, enabling threat actors to craft malicious requests and execute arbitrary commands on the system. There is evidence to suggest that the VPN appliance may have been compromised as early as December 3, 2023. Threat intelligence company Volexity attributes the attacks to a hacking group tracked as UTA0178, believed to be a Chinese nation-state actor.