ZeroHour
CyberScooppublished ()ingested @chrismvasq

CISA warns of hackers exploiting bug for end-of

criticalAdvisory exploited in the wildimportance 60CVE-2024-8190

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-8190
OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6

Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild.

Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim.

7.289% KEV
  • Ivanti Cloud Services Appliance 4.6 through Patch 518 (versions 4.6 Patch 518 and before)
moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts)
Full article231 words · extracted from cyberscoop.com · click to collapse

Ivanti's Cloud Service Appliance has a "high severity vulnerability" being exploited in the wild.

(Getty Images)

An end-of-life version of Ivanti’s cloud IT service management software has a recently released vulnerability that the Cybersecurity and Infrastructure Security Agency says is being exploited.

CISA warned that organizations outfitted with Ivanti’s Cloud Service Appliance version 4.6 and below are being targeted by hackers and the bug has been added to the known exploited vulnerabilities (KEV) list. The Utah-based company said on Friday that a “limited number of customers” have confirmed exploitation but did not provide further details.

Additionally, the bug is the last to be ported to the end-of-life version, Ivanti said, so organizations should update to CSA 5.0 for further security updates. The bug — an OS command injection vulnerability — allows a hacker with admin rights in the software to gain remote code execution of the device.

“CSA 5.0 is the only supported version and does not contain this vulnerability,” Ivanti noted. Additionally, Ivanti said “CSA configurations should be dual-homed with eth0 as an internal network.” 

The vulnerability — CVE-2024-8190 — was first released to the public Sept. 10 and at the time there were no known public exploits. To find evidence of compromise, Ivanti suggests reviewing CSA for new admin users.

Federal civilian agencies are required to mitigate the vulnerability within 60 days after being added to the KEV list.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ivanti-vulnerability-cisa-kev/