Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection

cve CVE-2024-37404 1 source, 1 claim · Watch

Metasploit exploit modules writes:
This module exploits a CRLF injection vulnerability in Ivanti Connect Secure to achieve remote code execution (CVE-2024-37404). Versions prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure versions prior to 22.7R1.1 are also vulnerable but this module doesn't support this software. Valid administrative credentials are required. A non-administrative user is also required and can be created using the administrative account, if needed. the claim

What each source says

PropertySourceSaidMeans here
Platform
platform
Metasploit exploit modulesLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "x86",
  "author": [
    "Richard Warren",
    "Christophe De La Fuente"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a CRLF injection vulnerability in Ivanti Connect\n          Secure to achieve remote code execution (CVE-2024-37404). Versions\n          prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure\n          versions prior to 22.7R1.1 are also vulnerable but this module\n          doesn't support this software.\n\n          Valid administrative credentials are required. A non-administrative\n          user is also required and can be created using the administrative\n          account, if needed.",
  "disclosure_date": "2024-10-08",
  "fullname": "exploit/linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:54:55 +0000",
  "name": "Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs",
      "account-logout"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb",
  "platform": "Linux",
  "post_auth": true,
  "rank": 600,
  "ref_name": "linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "references": [
    "CVE-2024-37404",
    "URL-https://attackerkb.com/topics/FI5vcuGwyM/cve-2024-37404",
    "URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-and-Policy-Secure-CVE-2024-37404",
    "URL-https://blog.amberwolf.com/blog/2024/october/cve-2024-37404-ivanti-connect-secure-authenticated-rce-via-openssl-crlf-injection/"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "x86",
  "author": [
    "Richard Warren",
    "Christophe De La Fuente"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a CRLF injection vulnerability in Ivanti Connect\n          Secure to achieve remote code execution (CVE-2024-37404). Versions\n          prior to 22.7R2.1 are vulnerable. Note that Ivanti Policy Secure\n          versions prior to 22.7R1.1 are also vulnerable but this module\n          doesn't support this software.\n\n          Valid administrative credentials are required. A non-administrative\n          user is also required and can be created using the administrative\n          account, if needed.",
  "disclosure_date": "2024-10-08",
  "fullname": "exploit/linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:54:55 +0000",
  "name": "Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs",
      "account-logout"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_37404.rb",
  "platform": "Linux",
  "post_auth": true,
  "rank": 600,
  "ref_name": "linux/http/ivanti_connect_secure_rce_cve_2024_37404",
  "references": [
    "CVE-2024-37404",
    "URL-https://attackerkb.com/topics/FI5vcuGwyM/cve-2024-37404",
    "URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-and-Policy-Secure-CVE-2024-37404",
    "URL-https://blog.amberwolf.com/blog/2024/october/cve-2024-37404-ivanti-connect-secure-authenticated-rce-via-openssl-crlf-injection/"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—

exploit

Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
zetlyn/cve-metasploit · 2024-10-08
platform Linux rank 600 source