[{"title":"Ivanti Connect Secure WEB COMPONENT Unauthenticated Remote Code Execution Exploit","body":"An authenticated user can exploit a command injection vulnerability in the web components of Ivanti Connect Secure (9.x and 22.x) to execute arbitrary commands. This module exploits two vulnerabilities. First, it leverages the lack of authentication in \u0022\/api\/v1\/totp\/user-backup-code\u0022, allowing unauthenticated access and path traversal. Then, it uses this vulnerability to access the system and execute remote commands in \u0022\/api\/v1\/license\/key-status\/path:node_name\u0022. The deployed agent will run with ROOT privileges.","created":"\u003Ctime datetime=\u00222024-06-28T00:00:00-05:00\u0022 class=\u0022datetime\u0022\u003EJune 28, 2024\u003C\/time\u003E\n","field_cve_link":"\u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2024-21887\u0022 target=\u0022_blank\u0022\u003ECVE-2024-21887\u003C\/a\u003E, \u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2023-46805\u0022 target=\u0022_blank\u0022\u003ECVE-2023-46805\u003C\/a\u003E","field_exploit_platform":"Linux","field_exploit_type":"Exploits \/ Remote Code Execution","field_product_name":"Impact"}]