3 More Ivanti Cloud Vulns Exploited in the Wild

Share This Post

In the latest wrinkle of what seems to be an ongoing saga of vulnerability concerns, Ivanti is notifying customers of three additional vulnerabilities found in its Cloud Services Appliance (CSA) that are being exploited in the wild.

There is limited exploitation of the vulnerabilities (CVE-2024-9379, CVE-2024-9380, and CVE-2024-9381) according to the vendor, which are being chained individually with a previously disclosed zero-day vulnerability (CVE-2024-8963) found in Ivanti’s CSA.

CVE-2024-9379 has a CVSS rating of 6.5 and allows a remote authenticated attacker with privileges to run SQL statements. CVE-2024-9380, with a CVSS score of 7.2, is an operating system command injection vulnerability in Ivanti CSA that can allow a remote authenticated attacker to obtain remote code execution with admin privileges. And lastly, CVE-2024-9381, carrying a CVSS score of 7.2, is a path traversal in Ivanti CSA before version 5.0 and allows a remote authenticated attacker to bypass restrictions with admin privileges.

The bugs were found on systems running CSA 4.6 patch 518 and prior, and there is no evidence of exploitation on any environments running CSA 5.0.

“Ivanti recommends reviewing the CSA for modified or newly added administrative users,” said Ivanti in its user recommendations for checking compromised devices. “We also recommend reviewing EDR alerts, if you have installed EDR or other security tools on your CSA. As this is an edge device, Ivanti strongly recommends using a layered approach to security and installing an EDR tool on the CSA.”

Should a user suspect that they have been compromised, its recommended they rebuild their CSA with version 5.0.

https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt50e6655190713fa9/6706bbb8227b3d78d16b7547/cloud1800_Skorzewiak_alamy.jpg?disable=upscale&width=1200&height=630&fit=crop

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.