Ivanti has released a security update to address an authentication bypass vulnerability and a command injection vulnerability in all supported versions of Connect Secure and Policy Secure gateways.
A cyber threat actor could exploit these vulnerabilities to take control of an affected system.
Ivanti reports active exploitation of both CVE-2023-46805 and CVE-2024-21887.
CISA urges users and administrators to immediately review Ivanti's security update and apply the current workaround.
CISA will update this alert as Ivanti releases patches.
This product is provided subject to this Notification and this Privacy & Use policy.
This Cyber News was published on www.cisa.gov. Publication date: Wed, 10 Jan 2024 19:13:06 +0000