QID 731164

Date Published: 2024-02-19

QID 731164: Ivanti Connect Secure Remote Code Execution (RCE) Vulnerability

Ivanti Connect Secure provides a seamless, cost-effective, SSL VPN solution for remote and mobile users from any web-enabled device to corporate resources.

CVE-2023-41719: A vulnerability exists on both branches of Ivanti Connect Secure (9.1Rx and 22x) below 22.6R2 or 9.1R18.5 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.

Affected Versions:
Ivanti Connect Secure 22.x
Ivanti Connect Secure 9.1Rx prior to 9.1.R18.5

Patched Versions:
Ivanti Connect Secure 22.4R1.1
Ivanti Connect Secure 22.5R2.3
Ivanti Connect Secure 22.6R2.2
Ivanti Connect Secure 9.1R18.5 (As per the vendor advisory, this version is tentatively scheduled to be released by the end of Q1)

QID Detection Logic: This QID checks for the installed version of Ivanti Connect Secure (ICS) by sending a GET request to the '/dana-cached/sc/PulseSecureInstallerService.exe' endpoint.

Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code on the vulnerable system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to upgrade their Ivanti Connect Secure instances to the latest version. For more information, please refer to the Ivanti Security Advisory.

    CVEs related to QID 731164

    Software Advisories
    Advisory ID Software Component Link
    000089503 URL Logo forums.ivanti.com/s/article/Security-patch-release-Ivanti-Connect-Secure-22-6R2-and-22-6R2-1?language=en_US