ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-8190
OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6

Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild.

Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim.

7.289% KEV
  • Ivanti Cloud Services Appliance 4.6 through Patch 518 (versions 4.6 Patch 518 and before)
moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts)
CVE-2024-8963
Unauthenticated Path Traversal in Ivanti Cloud Services Appliance

CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets.

Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions.

9.199% KEV
  • Ivanti Cloud Services Appliance (CSA) CSA 4.6.x before 4.6 Patch 519
moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted)
CVE-2024-9380
+1 in the same advisory: …9379
OS Command Injection RCE in Ivanti Cloud Services Appliance Admin Console

CVE-2024-9380 is an OS command injection flaw (CWE-77/CWE-78) in the admin web console of Ivanti Cloud Services Appliance (CSA), fixed in version 5.0.2. A remote attacker who is already authenticated with administrative privileges can inject arbitrary operating system commands through the console, which the appliance then executes. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). All CSA releases before 5.0.2 are affected, and the widely deployed 4.6.x line has reached End-of-Life, so EOL users must remove it from service or move to 5.0.x or later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-09, and contemporaneous reporting describes Chinese nation-state actors exploiting Ivanti CSA zero-days against French government and telecom targets, with a 63.2% EPSS probability of exploitation in the next 30 days (99th percentile).

Do: Upgrade Ivanti CSA to 5.0.2 or later; if you are running the End-of-Life 4.6.x line, either remove it from service or migrate to the supported 5.0.x line, per CISA's KEV required action. Restrict exposure of the admin web console (do not leave it directly internet-facing) and verify whether your appliance was targeted. Given reported nation-state exploitation of CSA zero-days, review appliance logs and admin credentials for signs of compromise.

7.263% KEV
  • Ivanti Endpoint Manager Cloud Services Appliance (CSA) all versions before 5.0.2, including the End-of-Life 4.6.x line
moderate≈ a few thousand internet-exposed CSA appliances; total installed base likely in the low tens of thousands
CVE-2025-20128
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of s

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

NVD description · AI analysis pending
7.52%
  • clamav clamav
  • clamav secure endpoint
  • clamav secure endpoint private cloud
CVE-2025-20156
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administra

A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.

NVD description · AI analysis pending
9.91%
  • cisco meeting management
CVE-2025-20165
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP reque

A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is due to improper memory handling for certain SIP requests. An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system. A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover.

NVD description · AI analysis pending
7.5<1%
  • cisco broadworks network server
Full article599 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 23, 2025Network Security / Vulnerability

Cisco has released software updates to address a critical security flaw impacting Meeting Management that could permit a remote, authenticated attacker to gain administrator privileges on susceptible instances.

The vulnerability, tracked as CVE-2025-20156, carries a CVSS score of 9.9 out 10.0. It has been described as a privilege escalation flaw in the REST API of Cisco Meeting Management.

"This vulnerability exists because proper authorization is not enforced upon REST API users," the company said in a Wednesday advisory. "An attacker could exploit this vulnerability by sending API requests to a specific endpoint."

"A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management."

The networking equipment major credited Ben Leonard-Lagarde of Modux for reporting the security shortcoming. It affects the following versions of the product irrespective of device configuration -

  • Cisco Meeting Management release version 3.9 (Patched in 3.9.1)
  • Cisco Meeting Management release versions 3.8 and earlier (Migrate to a fixed release)
  • Cisco Meeting Management release version 3.10 (Not vulnerable)

Cisco has also released patches to remediate a denial-of-service (DoS) flaw affecting BroadWorks that stems from improper memory handling for certain Session Initiation Protocol (SIP) requests (CVE-2025-20165, CVSS score: 7.5). The issue has been fixed in version RI.2024.11.

"An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system," it said.

"A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover."

A third vulnerability patched by Cisco is CVE-2025-20128 (CVSS score: 5.3), an integer underflow bug impacting the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV that could also result in a DoS condition.

The company, which acknowledged Google OSS-Fuzz for reporting the flaw, said it's aware of the existence of a proof-of-concept (PoC) exploit code, although there is no evidence it has been maliciously exploited in the wild.

CISA and FBI Detail Ivanti Exploit Chains

News of Cisco flaws comes as the U.S. government's cybersecurity and law enforcement agencies released technical details of two exploit chains weaponized by nation-state hacking crews to break into Ivanti's cloud service applications in September 2024.

The vulnerabilities in question are as follows -

The attack sequences, per the Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI), involved the abuse of CVE-2024-8963 in conjunction with CVE-2024-8190 and CVE-2024-9380 in one case, and CVE-2024-8963 and CVE-2024-9379 in the other.

It's worth noting that the first exploit chain was disclosed by Fortinet FortiGuard Labs in October 2024. In at least one instance, the threat actors are believed to have conducted lateral movement after gaining an initial foothold.

The second exploit chain has been found to leverage CVE-2024-8963 in combination with CVE-2024-9379 to obtain access to the target network, followed by unsuccessful attempts to implant web shells for persistence.

"Threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant web shells on victim networks," the agencies said. "Credentials and sensitive data stored within the affected Ivanti appliances should be considered compromised.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/cisco-fixes-critical-privilege.html