PULSE NAME
Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN
WHITE AlienVault 2024-01-11 Modified: 2024-02-10
8
IOCs
LOW VOLUME
Volexity has uncovered active in-the-wild exploitation of two vulnerabilities allowing unauthenticated remote code execution in Ivanti Connect Secure VPN appliances. An official security advisory and knowledge base article have been released by Ivanti that includes mitigation that should be applied immediately. However, a mitigation does not remedy a past or ongoing compromise. Systems should simultaneously be thoroughly analyzed per details in this post to look for signs of a breach.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (8)
All domain CVE
TYPEINDICATORDESCRIPTIONCREATED
domain symantke.com 2024-01-11
domain sessionserver.sh 2024-01-11
domain sessionserver.pl 2024-01-11
domain webb-institute.com 2024-01-11
domain gpoaccess.com 2024-01-11
domain dslogconfig.pm 2024-01-11
CVE CVE-2023-46805 2024-01-11
CVE CVE-2024-21887 2024-01-11