Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways | CISA

CISA and partners warn that threat actors are actively exploiting multiple Ivanti Connect Secure and Ivanti Policy Secure vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893) to achieve unauthenticated RCE, implant web shells, and exfiltrate credentials. CISA found the Ivanti Integrity Checker Tool can be bypassed and recommends assuming credentials are compromised, hunting IOCs, running the latest external ICT, and applying vendor patches. #IvantiConnectSecure #GLASSTOKEN

Keypoints

  • Multiple CVEs (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893 and related disclosures) are being chained to produce unauthenticated remote code execution against Ivanti Connect Secure and Policy Secure appliances.
  • Actors implant web shells (e.g., GLASSTOKEN, GIFTEDVISITOR, BUSHWALK, LIGHTWIRE, CHAINLINE, WARPWIRE, WIREFIRE) on internal and external servers to execute commands and maintain access.
  • CISA validated that Ivanti’s internal and external Integrity Checker Tool (ICT) can be deceived; web shells and persistence can remain after factory resets and upgrades.
  • Compromised appliances have been used to harvest base64-encoded cleartext AD credentials and NTLM hashes from LMDB database files and active sessions, enabling domain compromise.
  • Post-exploitation leverages native appliance tools and libraries (freerdp, ssh, telnet, nmap) and tooling like Sliver to move laterally and expand access.
  • Detection guidance includes YARA rules from Volexity, IoC tables, and recommended incident response actions: quarantine, reimage, reset credentials, and forensic collection.
  • CISA urges rapid patching, limiting outbound connections, restricting privileged authentication, and considering removal of affected devices from enterprise use.

MITRE Techniques

  • [T1190] Exploit Public-Facing Applications – Used to chain Ivanti CVEs for initial access and deploy web shells (‘…exploit the vulnerabilities to implant web shells, including GLASSTOKEN and GIFTEDVISITOR…’).
  • [T1505.003] Server Software Component: Web Shell – Web shells were implanted on internal/external web servers to execute commands and maintain access (‘…these web shells are used to execute commands on compromised devices.’).
  • [T1203] Exploitation for Client Execution – Vulnerabilities enabled unauthenticated remote code execution (RCE) via crafted requests (‘…achieve unauthenticated remote code execution (RCE)’).
  • [T1078] Valid Accounts – Harvested credentials and cached AD credentials were reused for lateral movement and domain access (‘…leverage compromised accounts to laterally move within internal systems via RDP, SBD, and SSH.’).
  • [T1059.001] Command and Scripting Interpreter: PowerShell – Attackers executed arbitrary PowerShell via decoded request payloads and Assembly.Load techniques (‘…decoded from hex to base64 decoded, then passed to Assembly.Load()…used to execute arbitrary powershell commands.’).
  • [T1003] OS Credential Dumping – Adversaries exfiltrated base64 cleartext AD passwords and NTLM hashes from LMDB data and backups (‘…exfiltrate domain administrator cleartext credentials’ and parse LMDB database files to disclose plaintext credentials and NTLM hashes.).

Indicators of Compromise

  • [Filename] malicious/modified Ivanti components – compcheckresult.cgi, lastauthserverused.js (modified to include web shells and credential harvesting).
  • [File hash] host-based artifacts – ed4b855941d6d7e07aacf016a2402c4c870876a050a4a547af194f5a9b47945f (Cav-0.1-py3.6.egg / WIREFIRE), 3d97f55a03ceb4f71671aa2ecf5b24e9 (compcheckresult.cgi), and several other hashes listed in Appendix B.
  • [Domain] command-and-control / credential collection – symantke[.]com, gpoaccess[.]com (attacker-controlled domains hosting WARPWIRE/WIREFIRE activity and credential collection).
  • [IP Address] exploitation and post-exploitation hosts – 88.119.169[.]227, 50.215.39[.]49 (and multiple other IPs associated with mass exploitation and UTA0178 activity).

The technical attack chain begins with exploitation of multiple Ivanti CVEs (notably CVE-2023-46805, CVE-2024-21887, CVE-2024-21893) to achieve unauthenticated RCE on public-facing Ivanti Connect Secure and Policy Secure appliances. Successful exploitation allowed attackers to upload and modify legitimate components (for example, compcheckresult.cgi and lastauthserverused.js) to insert web shells and credential-harvesting JavaScript; those implants were then used to run arbitrary commands, stage Sliver implants, and establish C2 communication with domains such as symantke[.]com.

Post-exploitation techniques included extraction of base64-encoded plaintext Active Directory credentials and NTLM hashes from LMDB database files and live session caches, using native appliance tools and common network utilities (freerdp, ssh, telnet, nmap) to perform internal reconnaissance and lateral movement, and modifying files/time-stomping and remounting runtime partitions to evade Ivanti’s Integrity Checker Tool (ICT). CISA’s lab validation shows root-level persistence can survive factory resets and upgrades because persistence artifacts can be stored on encrypted partitions that ICT scans do not reveal.

Detection and response steps focus on hunting and containment: deploy available YARA rules and IoCs to detect implants and web shells, assume stored user and service credentials on affected appliances are compromised, and if compromise is suspected quarantine/reimage affected hosts, reset all exposed credentials, collect memory/disk artifacts (LMDB data, modified CGI/JS files, process lists, network connections), and follow incident reporting channels. Apply Ivanti patches as released, limit outbound appliance connections, restrict privileged authentication, and consider removing affected devices from production until fully validated.

Read more: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b