Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29824 | Unauthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM) Core Server CVE-2024-29824 is a SQL injection flaw (CWE-89) in the Core server component of Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. An unauthenticated attacker who can reach the EPM Core server over the network can send crafted input that is passed unsafely to the underlying database, and the flaw ultimately permits execution of arbitrary code on the server. Successful exploitation gives an attacker control of the EPM Core server, which manages an organization's endpoint fleet, typically yielding broad enterprise-level privileges useful for lateral movement; ransomware use has not been confirmed. Any organization running an affected EPM Core server is exposed, though because the attack requires access to the same network, the primary risk is from attackers already inside the network or on compromised managed endpoints rather than direct internet-facing attacks. The vulnerability was added to CISA's KEV catalog on 2024-10-02, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile); a CVSS score is not yet available and no public proof-of-concept is known. Do: Apply Ivanti's patched service update for your EPM release immediately per the vendor's instructions, prioritizing any Core server reachable from user or untrusted network segments; the KEV listing gives federal agencies a mandatory remediation deadline. As interim mitigation, restrict network access to the EPM Core server's services to management networks and administrators, and hunt for anomalous database activity or unexpected process launches on Core servers. | 8.8 | 100% | KEV |
| largetens of thousands of enterprise deployments (order of ~10,000-100,000 EPM Core servers; exact install base unpublished) | |
| CVE-2024-8190 | OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6 Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild. Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim. | 7.2 | 89% | KEV |
| moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts) | |
| CVE-2024-8963 | Unauthenticated Path Traversal in Ivanti Cloud Services Appliance CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets. Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions. | 9.1 | 99% | KEV |
| moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted) | |
| CVE-2024-9380 +1 in the same advisory: …9379 | OS Command Injection RCE in Ivanti Cloud Services Appliance Admin Console CVE-2024-9380 is an OS command injection flaw (CWE-77/CWE-78) in the admin web console of Ivanti Cloud Services Appliance (CSA), fixed in version 5.0.2. A remote attacker who is already authenticated with administrative privileges can inject arbitrary operating system commands through the console, which the appliance then executes. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). All CSA releases before 5.0.2 are affected, and the widely deployed 4.6.x line has reached End-of-Life, so EOL users must remove it from service or move to 5.0.x or later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-09, and contemporaneous reporting describes Chinese nation-state actors exploiting Ivanti CSA zero-days against French government and telecom targets, with a 63.2% EPSS probability of exploitation in the next 30 days (99th percentile). Do: Upgrade Ivanti CSA to 5.0.2 or later; if you are running the End-of-Life 4.6.x line, either remove it from service or migrate to the supported 5.0.x line, per CISA's KEV required action. Restrict exposure of the admin web console (do not leave it directly internet-facing) and verify whether your appliance was targeted. Given reported nation-state exploitation of CSA zero-days, review appliance logs and admin credentials for signs of compromise. | 7.2 | 63% | KEV |
| moderate≈ a few thousand internet-exposed CSA appliances; total installed base likely in the low tens of thousands | |
| CVE-2024-9381 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. NVD description · AI analysis pending | 7.2 | 16% |
| — |
Full article581 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 08, 2024Zero-Day / Vulnerability
Ivanti has warned that three new security vulnerabilities impacting its Cloud Service Appliance (CSA) have come under active exploitation in the wild.
The zero-day flaws are being weaponized in conjunction with another flaw in CSA that the company patched last month, the Utah-based software services provider said.
Successful exploitation of these vulnerabilities could allow an authenticated attacker with admin privileges to bypass restrictions, run arbitrary SQL statements, or obtain remote code execution.
"We are aware of a limited number of customers running CSA 4.6 patch 518 and prior who have been exploited when CVE-2024-9379, CVE-2024-9380, or CVE-2024-9381 are chained with CVE-2024-8963," the company said.
There is no evidence of exploitation against customer environments running CSA 5.0. A brief description of the three shortcomings is as follows -
- CVE-2024-9379 (CVSS score: 6.5) - SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements
- CVE-2024-9380 (CVSS score: 7.2) - An operating system (OS) command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution
- CVE-2024-9381 (CVSS score: 7.2) - Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
The attacks observed by Ivanti involve combining the aforementioned flaws with CVE-2024-8963 (CVSS score: 9.4), a critical path traversal vulnerability that allows a remote unauthenticated attacker to access restricted functionality.
Ivanti said it discovered the three new flaws as part of its investigation into the exploitation of CVE-2024-8963 and CVE-2024-8190 (CVSS score: 7.2), another now-patched OS command injection bug in CSA that has also been abused in the wild.
Besides updating to the latest version (5.0.2), the company is recommending users to review the appliance for modified or newly added administrative users to look for signs of compromise, or check for alerts from endpoint detection and response (EDR) tools installed on the device.
The development comes less than a week after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a security flaw impacting Ivanti Endpoint Manager (EPM) that was fixed in May (CVE-2024-29824, CVSS score: 9.6) to the Known Exploited Vulnerabilities (KEV) catalog.
CVE-2024-9381 No Longer Considered Actively Exploited
Ivanti has since revised its original advisory, removing references to active exploitation of CVE-2024-9381. When reached for comment, Ivanti told The Hacker News that the flaw was inadvertently marked as exploited due to a "clerical error."
"The update [to the advisory] was to address a clerical error in our reporting," a spokesperson from Ivanti said. "CVE-2024-9381 was discovered internally, and we are not aware of any exploitation in the wild. Ivanti continues to strongly urge all customers who have not already done so to upgrade to CSA 5.0.2."
"We have observed limited exploitation of CSA 4.6 when CVE-2024-9379 or CVE-2024-9380 are chained with CVE-2024-8963, present in CSA 4.6 patch 518 and below, it could lead to unauthenticated remote code execution," the updated bulletin states.
The development has prompted CISA to add both CVE-2024-9379 and CVE-2024-9380 to the KEV catalog, requiring federal agencies to apply the patches by October 30, 2024.
(The story was updated after publication to note that CVE-2024-9381 is no longer being treated as an actively exploited flaw.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html