HTTP: Ivanti Connect Secure and Policy Secure OpenSSL CRLF Injection

This signature detects attempts to exploit a known vulnerability against Ivanti Connect Secure and Policy Secure. A successful attack can lead to arbitrary code execution.

Extended Description

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

References

CVE: CVE-2024-37404

Short Name
HTTP:CTS:IVANTI-CSPS-CRLF-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CRLF CVE-2024-37404 Connect Injection Ivanti OpenSSL Policy Secure and
Release Date
12/03/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown

Found a potential security threat?