Ivanti warns of another critical CSA flaw exploited in attacks

Teilen:

Today, Ivanti warned that threat actors are exploiting another Cloud Services Appliance (CSA) security flaw in attacks targeting a limited number of customers.

Tracked as CVE-2024-8963, this admin bypass vulnerability is caused by a path traversal weakness. Successful exploitation allows remote unauthenticated attackers to access restricted functionality on vulnerable CSA systems (used as gateways to provide enterprise users secure access to internal network resources).

Attackers are using exploits that chain CVE-2024-8963 with CVE-2024-8190 — a high-severity CSA command injection bug fixed last and tagged as actively exploited on Friday — to bypass admin authentication and execute arbitrary commands on unpatched appliances.

Read More

“The vulnerability was discovered as we were investigating the exploitation that Ivanti disclosed on 13 September,” Ivanti said today.

“As we were evaluating the root cause of this vulnerability, we discovered that the issue had been incidentally addressed with some of the functionality removal that had been included in patch 519.”

Ivanti advises administrators to review alerts from endpoint detection and response (EDR) or other security software and configuration settings and access privileges for new or modified administrative users to detect exploitation attempts.

They should also ensure dual-homed CSA configurations with eth0 as an internal network to drastically reduce the risk of exploitation.

“If you suspect compromise, Ivanti’s recommendation is that you rebuild your CSA with patch 519 (released 09/10/2024). We strongly recommend moving to CSA 5.0, where possible,” the company further cautioned on Thursday.

“Ivanti CSA 4.6 is End-of-Life, and no longer receives patches for OS or third-party libraries. Additionally, with the end-of-life status the fix released on 10 September is the last fix Ivanti will backport to that version.”

Federal agencies must patch as soon as possible

CISA has also added the CVE-2024-8190 and CVE-2024-8963 Ivanti CSA flaws to its Known Exploited Vulnerabilities catalog.

Federal Civilian Executive Branch (FCEB) agencies must now patch vulnerable appliances within three weeks by October 4 and October 10, respectively, as required by Binding Operational Directive (BOD) 22-01.

The company said last week that it had escalated internal scanning and testing capabilities and is also improving its responsible disclosure process to address potential security issues faster.

In recent months, several Ivanti flaws were exploited as zero-days in widespread attacks targeting the company’s VPN appliances and ICS, IPS, and ZTA gateways.

“This has caused a spike in discovery and disclosure, and we agree with CISAs statement that the responsible discovery and disclosure of CVEs is ‘a sign of healthy code analysis and testing community,'” Ivanti admitted.

In May, CISA and the FBI urged tech companies to review their software products before shipping to eliminate path traversal vulnerabilities.

Ivanti says it has over 7,000 partners worldwide, and more than 40,000 companies use its products to manage systems and IT assets.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:58 am, Jan. 27, 2025
Wetter-Symbol 8°C
L: 7° | H: 8°
wenige Wolken
Luftfeuchtigkeit: 86 %
Druck: 980 mb
Wind: 17 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:45 am
Sonnenuntergang: 4:40 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 8°°C 1 mm 100% 19 mph 82 % 986 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 20 mph 89 % 996 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
5° | 7°°C 1 mm 100% 13 mph 94 % 1005 mb 0 mm/h
Do. Jan. 30 9:00 pm
Wetter-Symbol
3° | 6°°C 1 mm 100% 13 mph 95 % 1026 mb 0 mm/h
Fr. Jan. 31 9:00 pm
Wetter-Symbol
2° | 5°°C 1 mm 100% 8 mph 93 % 1031 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
7° | 7°°C 0.8 mm 80% 14 mph 81 % 980 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 18 mph 73 % 982 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 5°°C 0.76 mm 76% 19 mph 82 % 986 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 15 mph 76 % 984 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 16 mph 81 % 984 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 17 mph 76 % 983 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 1 mm 100% 20 mph 89 % 980 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 19 mph 87 % 979 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€96,794.92
-3.54%
Ethereum(ETH)
€3,036.84
-4.80%
XRP(XRP)
€2.87
-4.22%
Fesseln(USDT)
€0.95
-0.02%
Solana(SOL)
€225.06
-8.83%
USDC(USDC)
€0.95
0.01%
Dogecoin(DOGE)
€0.314321
-7.37%
Shiba Inu(SHIB)
€0.000018
-6.78%
Pepe(PEPE)
€0.000012
-12.43%
Peanut das Eichhörnchen(PNUT)
€0.342367
3.03%
Nach oben scrollen