ZeroHour
Security Affairspublished ()ingested @securityaffairs

Ivanti fixed a maximum severity vulnerability in its CSA solution

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-11639
+2 in the same advisory: …11773 …11772
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

NVD description · AI analysis pending
9.8
group max
5%
  • ivanti cloud services appliance
CVE-2024-8963
Unauthenticated Path Traversal in Ivanti Cloud Services Appliance

CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets.

Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions.

9.199% KEV
  • Ivanti Cloud Services Appliance (CSA) CSA 4.6.x before 4.6 Patch 519
moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted)
CVE-2024-9380
+1 in the same advisory: …9379
OS Command Injection RCE in Ivanti Cloud Services Appliance Admin Console

CVE-2024-9380 is an OS command injection flaw (CWE-77/CWE-78) in the admin web console of Ivanti Cloud Services Appliance (CSA), fixed in version 5.0.2. A remote attacker who is already authenticated with administrative privileges can inject arbitrary operating system commands through the console, which the appliance then executes. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). All CSA releases before 5.0.2 are affected, and the widely deployed 4.6.x line has reached End-of-Life, so EOL users must remove it from service or move to 5.0.x or later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-09, and contemporaneous reporting describes Chinese nation-state actors exploiting Ivanti CSA zero-days against French government and telecom targets, with a 63.2% EPSS probability of exploitation in the next 30 days (99th percentile).

Do: Upgrade Ivanti CSA to 5.0.2 or later; if you are running the End-of-Life 4.6.x line, either remove it from service or migrate to the supported 5.0.x line, per CISA's KEV required action. Restrict exposure of the admin web console (do not leave it directly internet-facing) and verify whether your appliance was targeted. Given reported nation-state exploitation of CSA zero-days, review appliance logs and admin credentials for signs of compromise.

7.263% KEV
  • Ivanti Endpoint Manager Cloud Services Appliance (CSA) all versions before 5.0.2, including the End-of-Life 4.6.x line
moderate≈ a few thousand internet-exposed CSA appliances; total installed base likely in the low tens of thousands
CVE-2024-9381
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

NVD description · AI analysis pending
7.216%
  • ivanti endpoint manager cloud services appliance
Full article532 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 11, 2024

Ivanti addressed a critical authentication bypass vulnerability impacting its Cloud Services Appliance (CSA) solution.

Ivanti addressed a critical authentication bypass vulnerability, tracked as CVE-2024-11639 (CVSS score of 10), in its Cloud Services Appliance (CSA) solution.

A remote unauthenticated attacker can exploit the vulnerability to gain administrative access. 

The vulnerability was discovered by CrowdStrike’s Advanced Research Team and impacts 5.0.2 and prior.  

“An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access.” reads the advisory published by the company. 

The company also fixed a critical SQL injection vulnerability, tracked as CVE-2024-11772 (CVSS score of 9.1) in the admin web console of Ivanti CSA before version 5.0.3. A remote authenticated attacker with admin privileges can exploit the flaw to run arbitrary SQL statements.

The third issue fixed by the company is a critical SQL injection, tracked as CVE-2024-11773  (CVSS score of 9.1) in the admin web console of Ivanti CSA before version 5.0.3. A remote authenticated attacker with admin privileges can exploit the flaw to run arbitrary SQL statements too.

Ivanti released version CSA 5.0.3 to address the above issues, it also pointed out that is not aware of attacks in the wild exploiting the vulnerabilities.

“We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure. These vulnerabilities were disclosed through our responsible disclosure program.” concludes the advisory. “Currently, there is no known public exploitation of this these vulnerabilities that could be used to provide a list of indicators of compromise.”

In early October, the software company warned of three new security vulnerabilities (CVE-2024-9379, CVE-2024-9380, and CVE-2024-9381) in its Cloud Service Appliance (CSA) that are actively exploited in attacks in the wild.

Below are the descriptions of the three vulnerabilities:

  • CVE-2024-9379 (CVSS score 6.5) – a SQL injection in the admin web console of Ivanti CSA before version 5.0.2. A remote authenticated attacker with admin privileges can exploit the flaw to run arbitrary SQL statements.
  • CVE-2024-9380 (CVSS score 7.2) – an OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2. A remote authenticated attacker with admin privileges can exploit the vulnerability to achieve remote code execution.
  • CVE-2024-9381 (CVSS score 7.2) – a path traversal issue in Ivanti CSA before version 5.0.2. A remote authenticated attacker with admin privileges can exploit the flaw to bypass restrictions.

Threat actors are chaining these three vulnerabilities with the CSA zero-day CVE-2024-8963 (CVSS score of 9.4) that the software firm addressed in September.

Threat actors could exploit these vulnerabilities to carry out SQL injection attacks, execute arbitrary code via command injection, and bypass security restrictions by abusing a path traversal weakness on vulnerable CSA gateways.

“We are aware of a limited number of customers running CSA 4.6 patch 518 and prior who have been exploited when CVE-2024-9379, CVE-2024-9380 or CVE-2024-9381 are chained with CVE-2024-8963.” reads the advisory published by Ivanti. “We have no evidence of any other vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti products or solutions.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CSA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171850/breaking-news/ivanti-maximum-severity-flaw-csa-solution.html