CISA Flags Critical Ivanti vTM Vulnerability Amid Active Exploitation Concerns
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-7593 | Unauthenticated Admin Account Creation in Ivanti Virtual Traffic Manager CVE-2024-7593 is an authentication bypass (CWE-287, CWE-303) in Ivanti Virtual Traffic Manager (vTM), Ivanti's enterprise load-balancing and traffic-management product. An unauthenticated remote attacker can send crafted requests to the vulnerable management interface and create an administrator account of their choosing, effectively obtaining full administrative control. With admin access, an attacker can modify load-balancing and traffic-routing configurations and potentially pivot further into the networks the appliance serves. Any organization running an affected Ivanti vTM release is exposed; the affected version ranges are not specified in the available data, so administrators should consult Ivanti's advisory. Exploitation is confirmed in the wild (added to CISA KEV on 2024-09-24), EPSS assigns a 100% probability of exploitation within 30 days (top percentile), CVSS is not yet scored, no public proof-of-concept is known, and ransomware use is unknown. Do: Upgrade Virtual Traffic Manager to the fixed releases listed in Ivanti's security advisory for CVE-2024-7593; if patching is not immediately possible, follow vendor mitigations or discontinue use, as required under the CISA KEV listing (added 2024-09-24). In the meantime, restrict management-interface access to trusted networks and audit administrator accounts for unexpected or attacker-created admin entries. | 9.8 | 100% | KEV |
| moderateroughly 2,000-3,000 internet-exposed vTM instances (low thousands per public scans); total enterprise installs higher | |
| CVE-2024-8190 | OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6 Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild. Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim. | 7.2 | 89% | KEV |
| moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts) | |
| CVE-2024-8963 | Unauthenticated Path Traversal in Ivanti Cloud Services Appliance CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets. Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions. | 9.1 | 99% | KEV |
| moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted) |
Full article285 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 25, 2024Vulnerability / Cyber Attack
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting Ivanti Virtual Traffic Manager (vTM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability in question is CVE-2024-7593 (CVSS score: 9.8), which could be exploited by a remote unauthenticated attacker to bypass the authentication of the admin panel and create rogue administrative users.
"Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account," CISA said.
The issue was patched by Ivanti in vTM versions 22.2R1, 22.3R3, 22.5R2, 22.6R2, and 22.7R2 in August 2024.
The agency did not reveal any specifics on how the shortcoming is being weaponized in real-world attacks and who may be behind them, but Ivanti had previously noted that a proof-of-concept (PoC) is publicly available.
In light of the latest development, Federal Civilian Executive Branch (FCEB) agencies are required to remediate the identified flaw by October 15, 2024, to secure their networks.
In recent months, several flaws affecting Ivanti devices have come under active exploitation in the wild, including CVE-2024-8190 and CVE-2024-8963.
The software services provider acknowledged that it's aware of a "limited number of customers" who have been targeted by both the issues.
Data shared by Censys shows that there are 2,017 exposed Ivanti Cloud Service Appliance (CSA) instances online as of September 23, 2024, most of which are located in the U.S. It's currently not known how many of these are actually susceptible.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/09/cisa-flags-critical-ivanti-vtm.html