
1/23/2024 · Himanshu Anand, Radwa Radwan, Vaibhav Singhal
What this post added
This post details how Cloudflare's AI-powered WAF Attack Score proactively detected and blocked exploitation attempts for CVE-2023-46805 and CVE-2024-21887, zero-day vulnerabilities in Ivanti Connect Secure. It provides a technical analysis of the exploitation techniques, including directory traversal and command injection via crafted HTTP requests and JSON payloads. It also explains how the WAF Attack Score, particularly the 'WAF RCE Attack Score', identified these malicious requests before they were publicly disclosed, and highlights the rapid deployment of emergency managed rules to mitigate the threat.