Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Ivanti-Connect-Around-Scan — Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887. | Kitploit
Tools/GitHubGitHub/seajaysec/ivanti-connect-around-scan
ReconnaissanceVulnerability ScannersExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubseajaysec/ivanti-connect-around-scan

Ivanti-Connect-Around-Scan

Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
12362 years agoNot yet reviewed

Ivanti Connect Around Vulnerability Checker

  • Ivanti Connect Around Vulnerability Checker
    • Overview
    • Features
    • Types of Checks
      • WEB ACCESS
      • SYSTEM INFO
      • BYPASS DETECTED
    • Status Types Explanation
    • Getting Started
      • Requirements
      • Usage
        • Arguments
          • Target Specification
          • Custom Variables
          • Output Stylization
    • To Do
    • Contribution Guidelines
      • Reporting Issues
      • Submitting Pull Requests
    • Intended Use and Disclaimer
      • Purpose
      • Disclaimer
    • License
    • Acknowledgments
    • About Me

Overview

The Connect Around attack chain, involving CVE-2023-46805 and CVE-2024-21887, poses a significant threat to Ivanti Connect Secure & Policy Secure appliances. This attack chain enables unauthorized access and command execution on vulnerable systems. CVE-2023-46805 allows attackers to bypass authentication controls, while CVE-2024-21887, a command injection vulnerability, can be exploited without needing authentication when combined with the former. This duo of vulnerabilities necessitates urgent attention from organizations using Ivanti products, urging them to apply available mitigations as detailed in the Ivanti Community Forum.

In response to the need for organizations to validate mitigation status, the Ivanti Connect Around Vulnerability Checker has been developed. This script is designed to assess Ivanti Connect Secure & Policy Secure appliances for vulnerabilities associated with the Connect Around attack chain. It performs checks to verify the presence of these vulnerabilities and outputs the results in a CSV format. Multiple mitigation validation methodologies are employed to provide a comprehensive and reliable assessment.

Note: This script does not validate CVE-2024-21888 or CVE-2024-21893.

Features

  • Multiple validation methods: To ensure validation is comprehensive, multiple testing methods are performed against each target. Results are returned for each approach.
  • Concurrent Host Checks: Efficiently scans multiple hosts simultaneously, significantly reducing the time needed to assess vulnerabilities across a network.
  • Customizable Command-Line Arguments: Offers flexibility to define specific parameters such as input and output file paths, the number of concurrent threads for scanning, and selectable ports, ensuring tailored and precise scans.
  • Adaptive Output Management: Automatically generates output files with a default naming convention based on the current date and time, while also allowing users to specify custom filenames to suit their organizational needs.
  • Advanced Error Handling: Provides comprehensive error reporting, including detailed HTTP error codes, network connectivity issues, and other unexpected errors, enabling precise identification and troubleshooting of potential problems during scanning.
  • Port Flexibility: Allows users to define specific ports to scan (with 80 and 443 as defaults), catering to varied network configurations and enhancing the depth of vulnerability assessment.
  • Color-Coded Console Output: Optional feature for an enhanced user experience, offering color-coded output in the console for quick and easy identification of different scan statuses, improving readability and interpretation of results.

Types of Checks

The script conducts various checks to assess the security status of Ivanti Connect Secure systems. Each check is based on specific methodologies adapted from research within the information security community.

WEB ACCESS

  • Methodology: Adapted from WatchTowr Labs research.
  • Description: Requests the /api/v1/configuration/users/user-roles/user-role/rest-userrole1/web/web-bookmarks/bookmark endpoint without authentication.
  • Positive Result: Status displayed - "Vulnerable".
  • Negative Result: Status displayed - "Mitigated".
  • Research Link: WatchTowr Labs Research.

SYSTEM INFO

  • Methodology: Adapted from Stephen Fewer's research at Rapid7.
  • Description: Attempts to access the the /api/v1/system/system-information URI.
  • Positive Result: Status displayed - "Vulnerable".
  • Negative Result: Status displayed - "Mitigated".
  • Research Link: Metasploit Framework Module.

BYPASS DETECTED

  • Methodology: Adapted from Assetnote's research on alternative bypass URIs.
  • Description: Atempts to access the /admin/options/ URI.
  • Positive Result: Status displayed - "Vulnerable (Bypass Detected)".
  • Negative Result: Status displayed - "Not Vulnerable".
  • Research Link: Assetnote.

Each check provides insights into potential vulnerabilities. "Vulnerable" indicates a confirmed vulnerability, while "Mitigated" or "Not Vulnerable" signifies that the system appears secure against the specific vulnerability being tested.

Status Types Explanation

The script categorizes each check with specific status types, providing insight into the security posture of the scanned host. Here are the descriptions of each status type:

  • Mitigated: Indicates that the system has mitigations in place against the vulnerabilities checked. This status is returned when responses typical of a secure and patched system are detected.

  • Vulnerable: This status suggests that the system is vulnerable to the specific checks performed by the script. It is returned when the system exhibits known patterns or responses that indicate a vulnerability.

  • HTTP Error: Returned when the script encounters standard HTTP error responses (other than 403 Forbidden) from the target system. It usually indicates a problem with the web server or the request.

  • Network Issue: This status is used when the script encounters network-related issues, such as an inability to reach the host. It combines former statuses like "Host Unreachable" and "Network Error."

  • Timeout Error: Indicates that the request to the target timed out, suggesting potential network or configuration issues that prevented the script from completing its check.

  • Connection Error: Similar to "Timeout Error," this status is used when there are issues establishing a connection to the host, which could be due to network problems, incorrect hostnames, etc.

  • Ivanti Presence Inconclusive: Formerly known as "Attestation Needed," this status is returned when the script's checks do not yield definitive evidence of either vulnerability or mitigation. It suggests that further manual investigation is required to determine the security status of the system.

  • Vulnerable (Bypass Detected): Specific to the bypass vulnerability check, this status indicates that the system is vulnerable to the authentication bypass technique described in the script's methodology.

Each status provides a snapshot of the system's security posture concerning the vulnerabilities checked. Users should consider these statuses as initial indicators and, where necessary, conduct further manual investigations to confirm the system's actual security status.

Getting Started

Requirements

Download Tool