Website Security & Threat Management
How Cloudflare’s AI WAF proactively detected the Ivanti Connect Secure critical zero-day vulnerability

How Cloudflare’s AI WAF proactively detected the Ivanti Connect Secure critical zero-day vulnerability

1/23/2024 · Himanshu Anand, Radwa Radwan, Vaibhav Singhal

What this post added

This post details how Cloudflare's AI-powered WAF Attack Score proactively detected and blocked exploitation attempts for CVE-2023-46805 and CVE-2024-21887, zero-day vulnerabilities in Ivanti Connect Secure. It provides a technical analysis of the exploitation techniques, including directory traversal and command injection via crafted HTTP requests and JSON payloads. It also explains how the WAF Attack Score, particularly the 'WAF RCE Attack Score', identified these malicious requests before they were publicly disclosed, and highlights the rapid deployment of emergency managed rules to mitigate the threat.

Read the original post ↗