>> All posts

CVE-2024-21887: Ivanti Connect Secure command injection, actively exploited and chained to unauthenticated RCE

The short version: CVE-2024-21887 is a command-injection vulnerability in the web components of Ivanti Connect Secure and Ivanti Policy Secure. Crafted requests execute arbitrary commands on the appliance. On paper it expects an authenticated administrator — but chained with the authentication bypass CVE-2023-46805, that requirement disappears and the pair becomes unauthenticated remote code execution, exploited as a zero-day. It's in CISA's KEV catalog. Patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — in practice, as the payload half of an unauthenticated RCE chain
CVSS v3.0 (NVD)9.1 — Critical · AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS~99.99% · 99.99th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2024-01-22
Known exploited?Yes — exploited as a zero-day, chained with CVE-2023-46805
Vulnerability typeCommand injection → arbitrary command execution on the appliance
Requires authenticated session?On paper yes (admin); in practice no — chained with CVE-2023-46805 to bypass auth
AffectedIvanti Connect Secure 9.x and 22.x; Ivanti Policy Secure 9.x and 22.x
Fixed inPatched builds per Ivanti's advisory (staggered release began 2024-01-31); interim mitigation XML published earlier

What you need to know

CVE-2024-21887 lets specially crafted requests execute operating-system commands on the appliance. The base score assumes the attacker already holds administrator access (PR:H), which is why it's a 9.1 rather than a 10.

That assumption didn't hold in the real world:

  • It was chained to skip authentication. Paired with CVE-2023-46805, an attacker reaches the vulnerable endpoint without credentials and then injects commands — turning "authenticated admin RCE" into unauthenticated RCE.
  • The target is a perimeter security appliance. Code execution on Connect Secure means control of the device that terminates remote access into your network.
  • It was exploited before the fix. The chain was used in the wild as a zero-day, so affected appliances may have been compromised prior to patching.

How serious we see it

High — the 9.1 undersells the operational reality.

Read alone, this needs admin. Read the way attackers used it — behind an authentication bypass, on an internet-facing gateway, as a zero-day — it's unauthenticated remote code execution on a device that guards your network edge. We rate it by that reality. The bounded, reassuring part: it affects specific products and builds, fixes are published, and you can tell quickly whether it applies to you. The catch is the pre-patch window — patched and clean are different questions.

Recommendations

Straight from Ivanti's advisory and CISA:

  1. Patch now. Apply the fixed builds from Ivanti's advisory. Replace any earlier interim mitigation with the real patch.
  2. Hunt for prior compromise. Run Ivanti's external Integrity Checker Tool and review logs for signs of exploitation during the zero-day window.
  3. If compromised, respond fully. Rebuild from a known-good image and rotate all credentials, keys, and certificates the appliance held.
  4. Harden exposure. Limit who can reach the gateway; keep the management interface off the public internet.
  5. Confirm your exposure first. Verify whether you run an affected Connect Secure or Policy Secure build.

How BreachRisk sees it

BreachRisk starts from your external footprint. From little more than your domain it discovers internet-facing Ivanti Connect Secure and Policy Secure interfaces, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top because it's in KEV and because our take reflects the chained impact, not the 9.1 in isolation.

That outside-in, continuous view is exactly what helps when a gateway zero-day breaks: the exposed appliance is already on your radar, so you can go straight to patch-and-verify.

References

See your cyber risk, proven.