[{"title":"Ivanti Connect Secure SAML SSRF Unauthenticated Remote Code Execution Exploit","body":"This module chains together three vulnerabilities to deploy an agent. First, a vulnerability is used to obtain the exact version of Ivanti Connect Secure installed on the system. Next, the module exploits a second vulnerability that allows the attacker to access certain restricted resources without authentication, leveraging a flaw in the SAML component. Finally, the module uses a third vulnerability that enables remote code execution with elevated privileges in the management component, facilitating the injection and execution of the agent.","created":"\u003Ctime datetime=\u00222024-08-26T00:00:00-05:00\u0022 class=\u0022datetime\u0022\u003EAugust 26, 2024\u003C\/time\u003E\n","field_cve_link":"\u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2024-21887\u0022 target=\u0022_blank\u0022\u003ECVE-2024-21887\u003C\/a\u003E, \u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2023-46805\u0022 target=\u0022_blank\u0022\u003ECVE-2023-46805\u003C\/a\u003E, \u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2024-21893\u0022 target=\u0022_blank\u0022\u003ECVE-2024-21893\u003C\/a\u003E","field_exploit_platform":"Linux","field_exploit_type":"Exploits \/ Remote Code Execution","field_product_name":"Impact"}]