"Urgent: Ivanti Vulnerabilities Under Mass Exploitation"

1 min read
Source: BleepingComputer
"Urgent: Ivanti Vulnerabilities Under Mass Exploitation"
Photo: BleepingComputer
TL;DR Summary

Ivanti has warned of a new authentication bypass vulnerability (CVE-2024-22024) affecting its Connect Secure, Policy Secure, and ZTA gateways, urging immediate patching. The flaw allows remote attackers to access restricted resources without user interaction or authentication. Threat monitoring shows over 20,000 ICS VPN gateways exposed online, with Ivanti devices being heavily targeted in attacks. Security patches for the vulnerabilities were released on January 31, and Ivanti advises customers to factory reset vulnerable appliances before patching to block attackers' persistence.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

1 min

vs 2 min read

Condensed

76%

33579 words

Want the full story? Read the original article

Read on BleepingComputer