Ivanti.Connect.Secure.DSLog.Backdoor

description-logoDescription

This indicates that a connection to a backdoor on Ivanti Connect Secure was detected in the network.
The backdoor allows a remote attacker to execute arbitrary commands by sending a crafted HTTP request to the victim. The method through which it is installed is tracked as CVE-2024-21893.

affected-products-logoAffected Products

Ivanti Connect Secure (9.x, 22.x)
Ivanti Policy Secure (9.x, 22.x)
Ivanti Neurons for ZTA

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-03-13 27.748 Default_action:pass:drop
2024-02-15 26.734