Will Dormann on Nostr: This is great stuff. Ivanti Connect Secure CVE-2023-46805: You can access resources ...
This is great stuff.
Ivanti Connect Secure CVE-2023-46805: You can access resources by prefixing with any number of no-auth resources and directory traversal to where you want to go.
CVE-2024-21887: Command injection with certain targets.
Paying customers can mitigate the former.
https://attackerkb.com/topics/AdUh6by52K/cve-2023-46805/rapid7-analysis
Ivanti Connect Secure CVE-2023-46805: You can access resources by prefixing with any number of no-auth resources and directory traversal to where you want to go.
CVE-2024-21887: Command injection with certain targets.
Paying customers can mitigate the former.
https://attackerkb.com/topics/AdUh6by52K/cve-2023-46805/rapid7-analysis
![](https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/767/779/557/616/780/original/f2ac4e3acf3900b3.png)
![](https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/767/780/098/476/813/original/27e142c1c4f1e7f9.png)