Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s Emergency Directive 24-01 required Federal Civilian Executive Branch agencies using affected Ivanti Connect Secure or Ivanti Policy Secure gateways to disconnect them, investigate for compromise, rebuild and upgrade them, rotate exposed credentials and report their actions. The deadlines fell in February and March 2024 and have passed. The directive was an emergency response to active exploitation—not simply an instruction to install a patch.

What Emergency Directive 24-01 covered

CISA issued Emergency Directive 24-01 on January 19, 2024, for Federal Civilian Executive Branch (FCEB) agencies running Ivanti Connect Secure or Ivanti Policy Secure gateways. CISA’s January 31 supplemental direction set out additional required actions and deadlines. The directive applied to the named federal agencies; it was not a blanket federal order to every private organization using Ivanti products.

The vulnerabilities at the center of the response were CVE-2023-46805, an authentication-bypass flaw, and CVE-2024-21887, a command-injection flaw. CISA included both in its Known Exploited Vulnerabilities catalog in the federal remediation context. The directive addressed the risk of active exploitation of these flaws in the affected products.

Why CISA required more than patching

The concern was not limited to a vulnerable but otherwise untouched appliance. Attackers could use the flaws to capture credentials, deploy webshells, move laterally through an enterprise network, escalate privileges, and preserve access. A compromised gateway could remain a foothold even after the initial vulnerability was addressed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA and partner agencies warned that attackers might maintain access and stay quiet for an extended period. In its January 31, 2024 supplemental direction, CISA said: “Threat actors continue to leverage vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure solutions to capture credentials and drop webshells that enable further compromise of enterprise networks.” That persistence risk explains why the response included disconnecting appliances, hunting for signs of intrusion, rebuilding, and rotating credentials—not just installing an update.

What federal agencies were required to do

The January 31 supplemental direction required affected agencies to take the following actions. Its February and March dates are historical deadlines, not upcoming compliance dates.

Deadline in the directive Required action
As soon as possible, no later than February 2, 2024 Disconnect every affected appliance from agency networks; continue threat hunting; and isolate systems connected to the appliances.
As part of remediation Factory-reset and rebuild appliances, then upgrade them to a supported software version. Reimport configuration after rebuilding, and revoke and reissue certificates, keys, and passwords.
As part of incident response and reporting Report remediation status to CISA. Assume associated domain accounts were compromised, reset their passwords and tokens, and report those actions by March 1, 2024.

CISA stated in the supplemental direction, “Federal agencies are required to comply with these directives.” Those requirements were directed to FCEB agencies; organizations outside that scope should consult current Ivanti and CISA guidance and their own incident-response procedures.

What an organization should do if an Ivanti gateway may be compromised

For an organization outside the federal directive, the document is useful as a response model, but it does not replace current product-specific advice or an incident-response plan. A potentially compromised gateway should be treated as a security incident, not as an ordinary patching task.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check current advisories and identify the appliance. Confirm the product, software version, exposure, and applicable Ivanti security guidance. The 2024 directive does not establish which fixes or versions are current today.
  2. Assess exposure and containment. Determine whether the appliance is still connected and whether compromise is suspected or confirmed. Consider disconnecting or isolating it if continued operation could enable attacker access; coordinate that decision with security and network teams because it can interrupt remote access.
  3. Investigate before restoring trust. Hunt for indicators of compromise on the appliance and connected systems, and assess whether credentials or other secrets may have been exposed. A clean-looking gateway alone does not establish that an attacker never gained access.
  4. Rebuild and restore deliberately. Where compromise is suspected or confirmed, weigh rebuilding from a trusted state and installing a currently supported version against the risk of merely updating the existing appliance. Validate the restored service before returning it to production.
  5. Rotate potentially exposed credentials and keys. Scope rotation to accounts and secrets that could have been exposed, including relevant domain credentials, tokens, certificates, and keys. Coordinate timing and dependencies to avoid leaving old credentials active or causing avoidable outages.
  6. Document decisions and escalation. Record containment, investigation, rebuild, credential rotation, and validation steps. Involve incident-response specialists and meet any applicable reporting obligations.

How to choose between continued operation, isolation, and rebuilding

The right response depends on what is known about the appliance and what the organization can safely execute. Use these decision points rather than treating a software upgrade by itself as proof of remediation:

  • Still connected: If the gateway remains network-connected, assess whether immediate isolation is warranted while responders investigate. Balance containment against the operational impact of interrupting remote access.
  • Evidence of compromise: If compromise indicators exist—or cannot be ruled out—plan for incident response and a trusted rebuild rather than assuming an in-place upgrade removes attacker access.
  • Supported upgrade and factory reset: Confirm that a supported version and a reliable reset-and-rebuild path are available. Configuration should be restored carefully, not treated as inherently trustworthy.
  • Credential and certificate scope: Establish which accounts, passwords, tokens, keys, and certificates could have been exposed, and coordinate their revocation and reissuance.
  • Capacity to hunt and validate: Do not return a rebuilt gateway to service until the organization can investigate connected systems and validate the restored appliance and access paths.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the directive means now

The February 2 and March 1, 2024 deadlines have passed. Emergency Directive 24-01 and its supplemental direction remain useful historical references for understanding CISA’s response expectations for affected FCEB agencies, but they do not establish current Ivanti patch status or supersede later advisories. Before making a present-day remediation decision, consult CISA’s current directives and exploited-vulnerability information and Ivanti’s current security guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.