QID 731164
Date Published: 2024-02-19
QID 731164: Ivanti Connect Secure Remote Code Execution (RCE) Vulnerability
Ivanti Connect Secure provides a seamless, cost-effective, SSL VPN solution for remote and mobile users from any web-enabled device to corporate resources.
CVE-2023-41719: A vulnerability exists on both branches of Ivanti Connect Secure (9.1Rx and 22x) below 22.6R2 or 9.1R18.5 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.
Affected Versions:
Ivanti Connect Secure 22.x
Ivanti Connect Secure 9.1Rx prior to 9.1.R18.5
Patched Versions:
Ivanti Connect Secure 22.4R1.1
Ivanti Connect Secure 22.5R2.3
Ivanti Connect Secure 22.6R2.2
Ivanti Connect Secure 9.1R18.5 (As per the vendor advisory, this version is tentatively scheduled to be released by the end of Q1)
QID Detection Logic: This QID checks for the installed version of Ivanti Connect Secure (ICS) by sending a GET request to the '/dana-cached/sc/PulseSecureInstallerService.exe' endpoint.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code on the vulnerable system.
- Ivanti Security Advisory -
forums.ivanti.com/s/article/Security-patch-release-Ivanti-Connect-Secure-22-6R2-and-22-6R2-1?language=en_US
CVEs related to QID 731164
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000089503 |
|