Description
The Ivanti Connect Secure, Policy Secure Gate and Neurons have an SSRF (server-side request forgery) vulnerability. An attacker can use this vulnerability to bypass the fix for the authentication bypass vulnerability (CVE-2023-46805) and exploit the RCE vulnerability (CVE-2024-21887) to compromise the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure / Neurons
References
Related Vulnerabilities
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-4317)
Java Unspesificed Vulnerability (CVE-2019-2786)
Internet Information Services Other Vulnerability (CVE-2002-0224)
phpList Access of Resource Using Incompatible Type ('Type Confusion') Vulnerability (CVE-2020-8547)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5341)