Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection

zetlyn/cve-metasploit exploit cve CVE-2024-37404 known 2024-10-08

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb

Properties

platformLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 13:03 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "x86",
  "author": [
    "Richard Warren",
    "Christophe De La Fuente"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a CRLF injection vulnerability in Ivanti Connect\n          Secure to achieve remote code execution (CVE-2024-37404). Versions\n          prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure\n          versions prior to 22.7R1.1 are also vulnerable but this module\n          doesn't support this software.\n\n          Valid administrative credentials are required. A non-administrative\n          user is also required and can be created using the administrative\n          account, if needed.",
  "disclosure_date": "2024-10-08",
  "fullname": "exploit/linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:54:55 +0000",
  "name": "Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs",
      "account-logout"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb",
  "platform": "Linux",
  "post_auth": true,
  "rank": 600,
  "ref_name": "linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "references": [
    "CVE-2024-37404",
    "URL-https://attackerkb.com/topics/FI5vcuGwyM/cve-2024-37404",
    "URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-and-Policy-Secure-CVE-2024-37404",
    "URL-https://blog.amberwolf.com/blog/2024/october/cve-2024-37404-ivanti-connect-secure-authenticated-rce-via-openssl-crlf-injection/"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
rank600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 13:03 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "x86",
  "author": [
    "Richard Warren",
    "Christophe De La Fuente"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a CRLF injection vulnerability in Ivanti Connect\n          Secure to achieve remote code execution (CVE-2024-37404). Versions\n          prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure\n          versions prior to 22.7R1.1 are also vulnerable but this module\n          doesn't support this software.\n\n          Valid administrative credentials are required. A non-administrative\n          user is also required and can be created using the administrative\n          account, if needed.",
  "disclosure_date": "2024-10-08",
  "fullname": "exploit/linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:54:55 +0000",
  "name": "Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs",
      "account-logout"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb",
  "platform": "Linux",
  "post_auth": true,
  "rank": 600,
  "ref_name": "linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "references": [
    "CVE-2024-37404",
    "URL-https://attackerkb.com/topics/FI5vcuGwyM/cve-2024-37404",
    "URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-and-Policy-Secure-CVE-2024-37404",
    "URL-https://blog.amberwolf.com/blog/2024/october/cve-2024-37404-ivanti-connect-secure-authenticated-rce-via-openssl-crlf-injection/"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}

Text

This module exploits a CRLF injection vulnerability in Ivanti Connect Secure to achieve remote code execution (CVE-2024-37404). Versions prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure versions prior to 22.7R1.1 are also vulnerable but this module doesn't support this software. Valid administrative credentials are required. A non-administrative user is also required and can be created using the administrative account, if needed.