Nation-State Attackers Exploiting Ivanti CSA Flaws for Network Infiltration
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29824 | Unauthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM) Core Server CVE-2024-29824 is a SQL injection flaw (CWE-89) in the Core server component of Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. An unauthenticated attacker who can reach the EPM Core server over the network can send crafted input that is passed unsafely to the underlying database, and the flaw ultimately permits execution of arbitrary code on the server. Successful exploitation gives an attacker control of the EPM Core server, which manages an organization's endpoint fleet, typically yielding broad enterprise-level privileges useful for lateral movement; ransomware use has not been confirmed. Any organization running an affected EPM Core server is exposed, though because the attack requires access to the same network, the primary risk is from attackers already inside the network or on compromised managed endpoints rather than direct internet-facing attacks. The vulnerability was added to CISA's KEV catalog on 2024-10-02, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile); a CVSS score is not yet available and no public proof-of-concept is known. Do: Apply Ivanti's patched service update for your EPM release immediately per the vendor's instructions, prioritizing any Core server reachable from user or untrusted network segments; the KEV listing gives federal agencies a mandatory remediation deadline. As interim mitigation, restrict network access to the EPM Core server's services to management networks and administrators, and hunt for anomalous database activity or unexpected process launches on Core servers. | 8.8 | 100% | KEV |
| largetens of thousands of enterprise deployments (order of ~10,000-100,000 EPM Core servers; exact install base unpublished) | |
| CVE-2024-8190 | OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6 Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild. Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim. | 7.2 | 89% | KEV |
| moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts) | |
| CVE-2024-8963 | Unauthenticated Path Traversal in Ivanti Cloud Services Appliance CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets. Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions. | 9.1 | 99% | KEV |
| moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted) | |
| CVE-2024-9380 | OS Command Injection RCE in Ivanti Cloud Services Appliance Admin Console CVE-2024-9380 is an OS command injection flaw (CWE-77/CWE-78) in the admin web console of Ivanti Cloud Services Appliance (CSA), fixed in version 5.0.2. A remote attacker who is already authenticated with administrative privileges can inject arbitrary operating system commands through the console, which the appliance then executes. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). All CSA releases before 5.0.2 are affected, and the widely deployed 4.6.x line has reached End-of-Life, so EOL users must remove it from service or move to 5.0.x or later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-09, and contemporaneous reporting describes Chinese nation-state actors exploiting Ivanti CSA zero-days against French government and telecom targets, with a 63.2% EPSS probability of exploitation in the next 30 days (99th percentile). Do: Upgrade Ivanti CSA to 5.0.2 or later; if you are running the End-of-Life 4.6.x line, either remove it from service or migrate to the supported 5.0.x line, per CISA's KEV required action. Restrict exposure of the admin web console (do not leave it directly internet-facing) and verify whether your appliance was targeted. Given reported nation-state exploitation of CSA zero-days, review appliance logs and admin credentials for signs of compromise. | 7.2 | 63% | KEV |
| moderate≈ a few thousand internet-exposed CSA appliances; total installed base likely in the low tens of thousands |
Full article676 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 14, 2024Network Security / Vulnerability
A suspected nation-state adversary has been observed weaponizing three security flaws in Ivanti Cloud Service Appliance (CSA) as zero-days to perform a series of malicious actions.
That's according to findings from Fortinet FortiGuard Labs, which said the vulnerabilities were abused to gain unauthenticated access to the CSA, enumerate users configured in the appliance, and attempt to access the credentials of those users.
"The advanced adversaries were observed exploiting and chaining zero-day vulnerabilities to establish beachhead access in the victim's network," security researchers Faisal Abdul Malik Qureshi, John Simmons, Jared Betts, Luca Pugliese, Trent Healy, Ken Evans, and Robert Reyes said.
The flaws in question are listed below -
- CVE-2024-8190 (CVSS score: 7.2) - A command injection flaw in the resource /gsb/DateTimeTab.php
- CVE-2024-8963 (CVSS score: 9.4) - A path traversal vulnerability on the resource /client/index.php
- CVE-2024-9380 (CVSS score: 7.2) - An authenticated command injection vulnerability affecting the resource /gsb/reports.php
In the next stage, the stolen credentials associated with gsbadmin and admin were used to perform authenticated exploitation of the command injection vulnerability affecting the resource /gsb/reports.php in order to drop a web shell ("help.php").
"On September 10, 2024, when the advisory for CVE-2024-8190 was published by Ivanti, the threat actor, still active in the customer's network, 'patched' the command injection vulnerabilities in the resources /gsb/DateTimeTab.php, and /gsb/reports.php, making them unexploitable."
"In the past, threat actors have been observed to patch vulnerabilities after having exploited them, and gained foothold into the victim's network, to stop any other intruder from gaining access to the vulnerable asset(s), and potentially interfering with their attack operations."
![]() |
| SQLi vulnerability exploitation |
The unknown attackers have also been identified abusing CVE-2024-29824, a critical flaw impacting Ivanti Endpoint Manager (EPM), after compromising the internet-facing CSA appliance. Specifically, this involved enabling the xp_cmdshell stored procedure to achieve remote code execution.
It's worth noting that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in the first week of October 2024.
Some of the other activities included creating a new user called mssqlsvc, running reconnaissance commands, exfiltrating the results of those commands via a technique known as DNS tunneling using PowerShell code, and proxying traffic through the CSA appliance by means of an open-source tool named ReverseSocks5.
Also of note is the deployment of a rootkit in the form of a Linux kernel object ("sysinitd.ko") on the compromised CSA device. The activity was detected on September 7, 2024.
"The likely motive behind this was for the threat actor to maintain kernel-level persistence on the CSA device, which may survive even a factory reset," Fortinet researchers said.
The Linux Rootkit Detailed
In a follow-up analysis published on January 13, 2025, Fortinet revealed that the Linux rootkit deployed following the exploitation of security flaws in Ivanti CSA takes the form of a kernel module, which leverages a Netfilter hook to monitor for attacker-issued TCP packets.
"Once the attack-init packet is verified, the kernel module records the source IP and Port and, in some global variables, the destination IP and Port," the company said. "This ensures that subsequent traffic meeting the conditions will be recognized as coming from the attacker and only processed within the Netfilter hook function."
The module is also responsible for issuing various kernel API calls, including one to execute a user-space program from the kernel space. This framework enables the attacker to communicate with the infected system, allowing the commands passed in the TCP packets to be passed to the user-space process for execution with root privileges.
The user-space process works by creating a child process using a fork() system call and uses the "/bin/sh" shell to process the Linux commands sent by the threat actor. The output of the user-space process is then sent back to the attacker.
(The story was updated after publication to include additional details of the Linux rootkit.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/nation-state-attackers-exploiting.html
