Tag: Ivanti Connect Secure

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery
News

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

The notorious Mirai botnet is being used to take control of Ivanti Connect Secure (ICS) devices due to two recently discovered security vulnerabilities. Juniper Threat Labs' findings, which state that the botnet payload has been delivered via vulnerabilities CVE-2023-46805 and CVE-2024-21887, support this. An attacker can use CVE-2023-46805, an authentication bypass weakness, and CVE-2024-21887, a command injection vulnerability, to create an exploit chain that can be used to execute arbitrary code and take control of vulnerable instances. The network security company saw an attack chain in which the "/api/v1/license/key-status/;" endpoint, which is susceptible to command injection, is reached by using CVE-2023-46805 to inject the payload read more Mirai Botnet Exploits Ivanti Co...