{"id":695,"date":"2024-01-24T07:00:00","date_gmt":"2024-01-24T15:00:00","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=695"},"modified":"2024-01-23T13:42:40","modified_gmt":"2024-01-23T21:42:40","slug":"emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/","title":{"rendered":"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What are the issues?&nbsp;<\/h2>\n\n\n\n<p>Earlier this month, Ivanti disclosed two new vulnerabilities affecting their popular Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure remote access SSL VPN systems. Identified as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-46805\">CVE-2023-46805<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-21887\">CVE-2024-21887<\/a>, these vulnerabilities were assigned base scores of 8.2 (high) and 9.1 (critical) and affect software versions 9.x and 22.x.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What\u2019s the impact?&nbsp;<\/h2>\n\n\n\n<p>Because CVE-2023-46805 allows attackers to bypass control checks and CVE-2024-21887 gives authenticated administrators the ability to execute arbitrary commands, chaining these vulnerabilities together allows attackers to run unauthenticated commands on the exploited systems.&nbsp;<\/p>\n\n\n\n<p>Since Ivanti Connect Secure is used to give employees access to sensitive corporate resources from a variety of web-connected devices, these CVEs have a serious impact on companies&#8217; abilities to secure critical data. Their network access control (NAC) solution, Ivanti Policy Secure, also controls access to sensitive information by only providing network access to authorized devices and users and monitoring usage of critical applications.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are these issues currently being exploited?&nbsp;<\/h2>\n\n\n\n<p>Unfortunately for users, these issues are actively being exploited in the wild. Volexity and Mandiant have both identified instances of individuals and groups, including nation-state threat actors, taking advantage of CVE-2023-46805 and CVE-2024-21887.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Can it be patched?&nbsp;<\/h2>\n\n\n\n<p>No patch is available for these issues as of January 17th, 2024. However, Ivanti has announced plans to release patches on a staggered schedule beginning on January 22nd and ending on February 19th, 2024. In the meantime, customers are advised to <a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\">use a workaround<\/a> provided by Ivanti. Users can also use Ivanti\u2019s Integrity Checker Tool to identify evidence of compromise.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How does CyCognito identify assets vulnerable to CVE-2023-46805 and CVE-2024-21887?&nbsp;<\/h2>\n\n\n\n<p>CyCognito actively tests all customer assets for these vulnerabilities. First, the test attempts to append a subdirectory to the base URL attached to a potentially compromised asset. If this new URL is valid, the page is searched for key phrases, text, and a specific status associated with vulnerable versions of Connect Secure and Policy Secure.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How does this affect CyCognito users?&nbsp;<\/h2>\n\n\n\n<p>CyCognito customers will see a pop-up notification providing a short overview of this vulnerability, Ivanti\u2019s advised action, and a list of vulnerable assets.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"782\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1280x782.png\" alt=\"\" class=\"wp-image-696\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1280x782.png 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-512x313.png 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-768x469.png 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1536x938.png 1536w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44.png 1600w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n\n\n\n<p><em>Figure 1: A pop-up notification in the CyCognito dashboard notifying users about CVE-2023-46805 and CVE-2024-21887<\/em><\/p>\n\n\n\n<p>This notification provides shortcuts to read the full text of the issues advisory, check for IPs running the vulnerable software, investigate these CVEs within available issue data, and contact CyCognito customer support for assistance. Once patches are available, customers will also be able to identify patchable and already-patched assets.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"1356\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-45-1280x1356.png\" alt=\"\" class=\"wp-image-697\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-45-1280x1356.png 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-45-483x512.png 483w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-45-768x814.png 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-45-1450x1536.png 1450w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-45.png 1510w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n\n\n\n<p><em>Figure 2: Asset details and screenshot for an IP address asset in the CyCognito dashboard attached to an Ivanti Connect Secure device.<\/em>&nbsp;<\/p>\n\n\n\n<p>While Volexity identified over 1,700 compromised assets worldwide, CyCognito identified only 30 vulnerable assets under monitoring. Affected customers have already been contacted directly by their customer support team.&nbsp;<\/p>\n\n\n\n<p>If you\u2019re curious about your attack surface and want to understand your external risks, you may be interested in CyCognito. Check out our website and explore our platform with a self-guided, interactive <a href=\"https:\/\/app.getreprise.com\/launch\/V6Waa5X\">dashboard product tour<\/a>. To learn how CyCognito can help you find, actively test, and prioritize your vulnerable assets, please visit our <a href=\"\/contact\/\">Contact Us page<\/a> to schedule a demo.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform. <\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[19,41,58,132,57],"class_list":["post-695","post","type-post","status-publish","format-standard","hentry","category-research","tag-active-security-testing","tag-active-testing","tag-cve","tag-security-issue","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887 | CyCognito Blog<\/title>\n<meta name=\"description\" content=\"Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887\" \/>\n<meta property=\"og:description\" content=\"Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-24T15:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/banner-blog-2024-01-24-2400x1256-email.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"1256\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Emma Zaballos\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Emma Zaballos\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\"},\"author\":{\"name\":\"Emma Zaballos\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58\"},\"headline\":\"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887\",\"datePublished\":\"2024-01-24T15:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\"},\"wordCount\":560,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1280x782.png\",\"keywords\":[\"Active Security Testing\",\"Active Testing\",\"CVE\",\"Security Issue\",\"Vulnerability\"],\"articleSection\":[\"Research\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\",\"name\":\"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887 | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1280x782.png\",\"datePublished\":\"2024-01-24T15:00:00+00:00\",\"description\":\"Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44.png\",\"width\":1600,\"height\":977},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58\",\"name\":\"Emma Zaballos\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g\",\"caption\":\"Emma Zaballos\"},\"description\":\"Product Marketing Manager\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/emma-zaballos\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887 | CyCognito Blog","description":"Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/","og_locale":"en_US","og_type":"article","og_title":"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887","og_description":"Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform.","og_url":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/","og_site_name":"CyCognito Blog","article_published_time":"2024-01-24T15:00:00+00:00","og_image":[{"width":2400,"height":1256,"url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/banner-blog-2024-01-24-2400x1256-email.jpg","type":"image\/jpeg"}],"author":"Emma Zaballos","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Emma Zaballos","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/"},"author":{"name":"Emma Zaballos","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58"},"headline":"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887","datePublished":"2024-01-24T15:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/"},"wordCount":560,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1280x782.png","keywords":["Active Security Testing","Active Testing","CVE","Security Issue","Vulnerability"],"articleSection":["Research"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/","url":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/","name":"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887 | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44-1280x782.png","datePublished":"2024-01-24T15:00:00+00:00","description":"Two security issues affecting the popular Ivanti Connect Secure and Ivanti Policy Secure remote access SSL VPN systems can be chained together to give unauthenticated attackers remote access to critical systems. CyCognito\u2019s active testing protects our current customers and delivers key insights about these vulnerabilities in the CyCognito platform.","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#primaryimage","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-44.png","width":1600,"height":977},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/emerging-security-issue-ivanti-vulnerabilities-cve-2023-46805-and-cve-2024-21887\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Emerging Security Issue: Ivanti Vulnerabilities CVE-2023-46805 and CVE-2024-21887"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58","name":"Emma Zaballos","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g","caption":"Emma Zaballos"},"description":"Product Marketing Manager","url":"https:\/\/www.cycognito.com\/blog\/author\/emma-zaballos\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=695"}],"version-history":[{"count":2,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/695\/revisions"}],"predecessor-version":[{"id":700,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/695\/revisions\/700"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=695"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}