CISA took two systems offline after Ivanti gateway flaws were exploited
- Organization
- Cybersecurity and Infrastructure Security Agency (CISA)
- Exploit
- Hacking
- Industry
- Government
The US Cybersecurity and Infrastructure Security Agency confirmed in early March 2024 that it had been compromised the previous month through vulnerabilities in Ivanti products, and that it had pulled two systems offline in response.
CISA declined to name the affected systems or say what data had been reached, stating only that the impact was limited to two systems which it immediately took offline. A source with knowledge of the situation told The Record that the systems were the Infrastructure Protection Gateway, which holds information about how US critical infrastructure is interconnected, and the Chemical Security Assessment Tool, the repository for private sector site security plans and security vulnerability assessments. The agency neither confirmed nor denied those identifications.
The route in was a set of flaws in Ivanti Connect Secure and Policy Secure gateways tracked as CVE-2023-46805, CVE-2024-21887 and CVE-2024-21893. CISA had itself ordered federal civilian agencies to disconnect affected Ivanti appliances weeks earlier and had issued advisories, including a joint alert on February 29, warning that the flaws were being actively exploited.
The agency did not attribute the activity. Nextgov reported that there was no operational impact and that the systems involved were already scheduled for replacement. In a statement CISA said the episode was a reminder that any organization can be affected by a cyber vulnerability and that having an incident response plan in place is a necessary component of resilience.