Description
This module exploits a CRLF injection vulnerability in Ivanti Connect Secure to achieve remote code execution (CVE-2024-37404). Versions prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure versions prior to 22.7R1.1 are also vulnerable but this module doesn't support this software.
Valid administrative credentials are required. A non-administrative user is also required and can be created using the administrative account, if needed.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/ivanti/connect_secure_rce_cve_2024_37404msf undefined(connect_secure_rce_cve_2024_37404) > show actions ...actions...msf undefined(connect_secure_rce_cve_2024_37404) > set ACTION < action-name >msf undefined(connect_secure_rce_cve_2024_37404) > show options ...show and set options...msf undefined(connect_secure_rce_cve_2024_37404) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub