Skip to main content
CVE Vulnerability Database

CVE-2024-9844: Ivanti Connect Secure Auth Bypass Flaw

CVE-2024-9844 is an authentication bypass vulnerability in Ivanti Connect Secure that allows authenticated attackers to bypass server-side restrictions. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-9844 Overview

CVE-2024-9844 affects the Secure Application Manager (SAM) component of Ivanti Connect Secure prior to version 22.7R2.4. The flaw results from insufficient server-side controls, allowing a remote authenticated attacker to bypass restrictions enforced by the appliance. Ivanti disclosed the issue in its December 2024 security advisory alongside several other vulnerabilities affecting Connect Secure and Policy Secure.

The weakness is categorized under [CWE-602] (Client-Side Enforcement of Server-Side Security), meaning trust decisions that should be validated on the server were left to client-side controls. Successful exploitation impacts confidentiality, integrity, and availability of the appliance.

Critical Impact

An authenticated remote attacker can bypass Secure Application Manager restrictions on affected Ivanti Connect Secure gateways, potentially expanding access to internal resources reachable through the VPN.

Affected Products

  • Ivanti Connect Secure versions prior to 22.7R2.4
  • Ivanti Connect Secure 22.7 (base and R1.x releases R1 through R1.5)
  • Ivanti Connect Secure 22.7R2, 22.7R2.1, 22.7R2.2, and 22.7R2.3

Discovery Timeline

  • 2024-12-10 - CVE-2024-9844 published to NVD as part of Ivanti's December 2024 Security Advisory
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-9844

Vulnerability Analysis

The Secure Application Manager (SAM) is a Connect Secure feature that brokers application-layer traffic between remote clients and internal resources. It enforces per-user and per-role restrictions on which internal applications, hosts, and ports a session may reach. CVE-2024-9844 arises because those restrictions are not fully validated on the server side.

An attacker who already holds valid credentials on the gateway can craft SAM traffic that violates the configured policy. Because the server relies on client-supplied state, the gateway accepts the request and proxies it to a target that the user's role should not permit. The result is a policy bypass that widens the attacker's reach into the internal network.

The attack requires network access to the VPN endpoint and low-privilege authentication. No user interaction is needed, and the scope stays within the vulnerable component, but the attacker gains unauthorized read, write, and disruption capability against resources exposed through SAM.

Root Cause

The root cause is a [CWE-602] pattern in the SAM broker. Access-control decisions that should be re-evaluated on the server are inferred from client-provided parameters. When the client manipulates those parameters, the server enforces the manipulated policy rather than the authoritative one bound to the session.

Attack Vector

Exploitation is remote and authenticated. The attacker connects to the Connect Secure gateway over the network, completes authentication with any valid low-privilege account, and then sends malformed SAM tunneling requests. The gateway forwards the traffic to internal destinations the account should not be able to reach.

No public proof-of-concept, exploit module, or CISA KEV listing is associated with this CVE at the time of writing. See the Ivanti December 2024 Security Advisory for vendor technical detail.

Detection Methods for CVE-2024-9844

Indicators of Compromise

  • Authenticated VPN sessions initiating SAM tunneled connections to internal hosts or ports that fall outside the user's assigned role policy.
  • Unexpected east-west traffic originating from the Connect Secure appliance's internal interface toward sensitive segments.
  • Repeated SAM connection attempts from a single account against varied internal IP ranges, indicating enumeration.

Detection Strategies

  • Compare SAM session logs against configured role-based resource policies and alert on any destination that is not explicitly permitted for the authenticating role.
  • Baseline per-user SAM destination sets and flag sudden expansion in the number of unique internal hosts or ports contacted.
  • Correlate VPN authentication events with downstream connection logs from internal network sensors to identify traffic that should have been blocked at the gateway.

Monitoring Recommendations

  • Forward Connect Secure syslog, authentication, and SAM session events into a centralized SIEM for retention and correlation.
  • Monitor administrative changes to SAM resource policies for unexpected modifications that could mask policy bypass.
  • Watch for authentication anomalies such as new geolocations, impossible travel, or credential reuse that could precede exploitation by an authenticated attacker.

How to Mitigate CVE-2024-9844

Immediate Actions Required

  • Upgrade all Ivanti Connect Secure appliances to version 22.7R2.4 or later without delay.
  • Review SAM role and resource policies to confirm least-privilege scoping for every user role.
  • Rotate credentials and audit account activity for any user that could have accessed the appliance before patching.
  • Inspect historical SAM logs for connection attempts to internal resources outside expected role boundaries.

Patch Information

Ivanti resolved CVE-2024-9844 in Connect Secure 22.7R2.4. Full remediation details, download locations, and additional CVEs addressed in the same release are documented in the Ivanti December 2024 Security Advisory.

Workarounds

  • No vendor-supplied workaround exists; upgrading to 22.7R2.4 is the only supported remediation.
  • Where immediate patching is not possible, restrict which accounts can authenticate to the gateway and disable SAM for roles that do not require it.
  • Enforce multi-factor authentication on all VPN accounts to raise the barrier for the authenticated precondition.
  • Place additional network segmentation and access controls between the Connect Secure appliance and sensitive internal systems to limit blast radius.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.