Ivanti Connect Secure: Why Patching Was Not Enough
CISA's February 2024 advisory documented active exploitation of vulnerabilities in Ivanti Connect Secure and Policy Secure gateways. Threat actors deployed web shells, harvested credentials, and in some incidents moved into domain environments.
The advisory also described bypasses of initial mitigations. That history reinforces a durable rule for internet-facing security appliances: follow current vendor guidance and investigate the device's integrity, not only its patch level.
The gateway was both entry point and evidence source
Successful exploitation could place attacker code on the appliance and expose credentials stored or processed there. Normal-looking remote access after compromise could then rely on stolen credentials rather than repeated vulnerability exploitation.
Logs kept only on the gateway may be incomplete or altered. Centralized identity, network, endpoint, DNS, and administrative telemetry is necessary to understand what happened beyond the appliance.
Use a staged containment and recovery plan
Identify all physical, virtual, standby, and test instances. Preserve available evidence, follow current integrity-check and remediation instructions, and isolate systems when the vendor or investigation requires it.
Reset or rotate affected credentials and secrets based on exposure, then hunt internal systems for activity originating from the gateway. Validate the rebuilt or upgraded device before restoring trust and monitor closely afterward.
- Treat integrity-check failure as an incident.
- Assume stolen credentials may outlive the original exploit.
- Include dormant and disaster-recovery appliances.
- Use independent logs to scope lateral movement.
Put the lesson into practice
- Inventory and classify every Ivanti gateway.
- Preserve evidence and run current integrity procedures.
- Apply supported fixes or rebuild as directed.
- Rotate exposed credentials and investigate internal access.
- Validate and monitor the restored service.
Related Outfaze guidance
- Patch management
- Vulnerability assessment
- Managed detection and response
- Digital forensics and incident response
- Managed next-generation firewall
