Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation
There has been widespread exploitation of a recently discovered server-side request forgery (SSRF) vulnerability affecting the Ivanti Connect Secure and Policy Secure products.
The Shadowserver Foundation said that, among other things, it saw exploitation attempts coming from over 170 distinct IP addresses to create a reverse shell.
The attacks take advantage of CVE-2024-21893 (CVSS score: 8.2), an SSRF vulnerability in the SAML part of Neurons for ZTA, Policy Secure, and Ivanti Connect Secure that permits an attacker to get unauthorized access to resources that would otherwise be prohibited read more Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough co...

