Security News > 2024 > February > Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor
![Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor](/static/build/img/news/hackers-exploit-ivanti-ssrf-flaw-to-deploy-new-dslog-backdoor-medium.jpg)
Hackers are exploiting a server-side request forgery vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA gateways to deploy the new DSLog backdoor on vulnerable devices.
The flaw impacts the SAML component of the mentioned products and allows attackers to bypass authentication and access restricted resources on Ivanti gateways running versions 9.x and 22.x. The updates that fix the problem are Ivanti Connect Secure versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1 and 22.5R2.2, Ivanti Policy Secure version 22.5R1.1, and ZTA version 22.6R1.3.
A new report by Orange Cyberdefense confirms the successful exploitation of CVE-2024-21893 to install a new backdoor named DSLog that allows the threat actors to execute commands on compromised Ivanti servers remotely.
The backdoor is inserted into the DSLog file, responsible for logging various types of authenticated web requests and system logs.
Orange says the DSLog backdoor can run "Any commands" on the breached device received via HTTP requests by the attackers, with the command included in a query parameter named 'cdi.
It is recommended to follow the latest recommendations by Ivanti to mitigate all threats targeting the vendor's products leveraging this SSRF or any of the other recently disclosed vulnerabilities impacting Ivanti devices.
News URL
Related news
- Hackers Exploit Legitimate Websites to Deliver BadSpace Windows Backdoor (source)
- Hackers Exploit Legitimate Packer Software to Spread Malware Undetected (source)
- Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells (source)
- China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally (source)
- Hackers exploit critical D-Link DIR-859 router flaw to steal passwords (source)
- Hackers use PoC exploits in attacks 22 minutes after release (source)
- Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks (source)
- Chinese hackers deploy new Macma macOS backdoor version (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-31 | CVE-2024-21893 | Server-Side Request Forgery (SSRF) vulnerability in Ivanti Connect Secure and Policy Secure A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication. | 8.2 |