QID 731126

Date Published: 2024-02-01

QID 731126: Ivanti Connect Secure and Ivanti Policy Secure Privilege Escalation Vulnerability (000090322)

Ivanti Connect Secure (ICS), formerly known as Pulse Connect Secure and Ivanti Policy Secure Gateway contain the following vulnerabilities:

  • CVE-2024-21888: A privilege escalation vulnerability in web component allows a user to elevate privileges to that of an administrator.
  • CVE-2024-21893: A server-side request forgery vulnerability in the SAML component allows an attacker to access certain restricted resources without authentication.
Affected Software:
Ivanti Connect Secure (9.x, 22.x)

QID Detection Logic:
This unauthenticated QID verifies the following endpoints:

  • api/v1/totp/user-backup-code/../../system/system-information
  • dana-na/nc/nc_gina_ver.txt
Additionally, this QID checks for installed vulnerable version of Ivanti Connect Secure (ICS) by requesting for /dana-cached/sc/PulseSecureInstallerService.exe and extracting the version from the binary.

NOTE: This QID currently does not check for applied mitigation.

Successful exploitation of this vulnerability allows an unauthenticated, remote attacker to elevate privileges and execute arbitrary code or transmit server-side request forgery requests and access sensitive resources.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to 000090322 for information pertaining to remediating these vulnerabilities.

    CVEs related to QID 731126

    Software Advisories
    Advisory ID Software Component Link
    000090322 URL Logo forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US