National Cyber Warfare Foundation (NCWF) Forums


Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation


0 user ratings
2024-02-06 08:08:20
milo
Blue Team (CND) , Attacks

 - archive -- 
A recently disclosed server-side request forgery (SSRF) vulnerability impacting Ivanti Connect Secure and Policy Secure products has come under mass exploitation.
The Shadowserver Foundation said it observed exploitation attempts originating from more than 170 unique IP addresses that aim to establish a reverse shell, among others.
The attacks exploit CVE-2024-21893 (CVSS



Source: TheHackerNews
Source Link: https://thehackernews.com/2024/02/recently-disclosed-ssrf-flaw-in-ivanti.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



© Copyright 2012 through 2024 - National Cyber War Foundation - All rights reserved worldwide.