Target Industry
Indiscriminate, opportunistic targeting.
Overview
Ivanti has released critical security updates to address multiple high-severity vulnerabilities affecting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA). These vulnerabilities, with CVSS scores as high as 9.9, could be exploited by remote authenticated attackers to achieve arbitrary code execution.
These vulnerabilities are identified as:
- CVE-2024-38657 (CVSS 9.1): External file name control in Ivanti Connect Secure (pre-22.7R2.4) and Policy Secure (pre-22.7R1.3) allows remote authenticated attackers with admin privileges to write arbitrary files
- CVE-2025-22467 (CVSS 9.9): Stack-based buffer overflow in Ivanti Connect Secure (pre-22.7R2.6) enables remote authenticated attackers to execute arbitrary code
- CVE-2024-10644 (CVSS 9.1): Code injection in Ivanti Connect Secure (pre-22.7R2.4) and Policy Secure (pre-22.7R1.3) allows remote authenticated attackers with admin privileges to execute arbitrary code
- CVE-2024-47908 (CVSS 9.1): OS command injection in the admin web console of Ivanti CSA (pre-5.0.5) allows remote authenticated attackers with admin privileges to execute arbitrary code.
Impact
Four critical vulnerabilities in Ivanti products allow remote authenticated attackers to write arbitrary files, execute arbitrary code, and perform command injections, leading to potential system compromise and unauthorised access.
Detailed Information
- CVE-2024-38657 (CVSS 9.1): Allows remote authenticated attackers with admin privileges to write arbitrary files. This can lead to unauthorised file modifications, data corruption, or the introduction of malicious files, compromising system integrity and potentially enabling further attacks.
- CVE-2025-22467 (CVSS 9.9): Enables remote authenticated attackers to execute arbitrary code due to a stack-based buffer overflow. This can lead to complete system compromise, allowing attackers to take full control of the affected system, execute malicious code, steal sensitive information, and disrupt services.
- CVE-2024-10644 (CVSS 9.1): Allows remote authenticated attackers with admin privileges to inject and execute arbitrary code. This can result in unauthorised actions within the system, including data theft, system manipulation, and potential further exploitation of network-connected resources.
- CVE-2024-47908 (CVSS 9.1): Permits remote authenticated attackers with admin privileges to execute arbitrary commands on the operating system via command injection in the admin web console. This can lead to full system compromise, unauthorised access to sensitive data, and the ability to disrupt or manipulate system operations.
Vulnerability Detection
Multiple Ivanti products are vulnerable to critical security flaws in specific versions, necessitating immediate updates to the latest secure releases.
CVE-2024-38657
- Ivanti Connect Secure versions before 22.7R2.4
- Ivanti Policy Secure versions before 22.7R1.3
CVE-2025-22467
- Ivanti Connect Secure versions before 22.7R2.6
CVE-2024-10644
- Ivanti Connect Secure versions before 22.7R2.4
- Ivanti Policy Secure versions before 22.7R1.3
CVE-2024-47908
- Ivanti Cloud Services Application (CSA) versions before 5.0.5
Exploitation
The company has stated that there is no current evidence of these vulnerabilities being exploited in the wild. However, given the history of Ivanti appliances being frequently targeted and weaponised by malicious actors, it is crucial for users to promptly apply the latest security patches. Ensuring these updates are implemented is essential to mitigate the risk of potential exploitation and to maintain the security and integrity of the affected systems.
Containment, Mitigations & Remediation
A patch has been released to remediate this vulnerability. It is strongly recommended that users apply this update immediately to ensure their systems are protected against potential exploitation.
Threat Landscape
Ivanti’s products, including Connect Secure and Policy Secure, are widely deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. These solutions enable secure remote access and support for zero-trust access frameworks, making them high-value targets for cyber attackers.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Further Information
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US
- https://cvefeed.io/vuln/detail/CVE-2024-10644
- https://thehackernews.com/2025/02/ivanti-patches-critical-flaws-in.html
- https://vulnerability.circl.lu/bundle/85f9fd3a-b2ef-443b-b091-2cad7418236f












