ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Ivanti Endpoint Manager Flaw Actively Targeted, CISA Warns Agencies to Patch

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-29824
Unauthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM) Core Server

CVE-2024-29824 is a SQL injection flaw (CWE-89) in the Core server component of Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. An unauthenticated attacker who can reach the EPM Core server over the network can send crafted input that is passed unsafely to the underlying database, and the flaw ultimately permits execution of arbitrary code on the server. Successful exploitation gives an attacker control of the EPM Core server, which manages an organization's endpoint fleet, typically yielding broad enterprise-level privileges useful for lateral movement; ransomware use has not been confirmed. Any organization running an affected EPM Core server is exposed, though because the attack requires access to the same network, the primary risk is from attackers already inside the network or on compromised managed endpoints rather than direct internet-facing attacks. The vulnerability was added to CISA's KEV catalog on 2024-10-02, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile); a CVSS score is not yet available and no public proof-of-concept is known.

Do: Apply Ivanti's patched service update for your EPM release immediately per the vendor's instructions, prioritizing any Core server reachable from user or untrusted network segments; the KEV listing gives federal agencies a mandatory remediation deadline. As interim mitigation, restrict network access to the EPM Core server's services to management networks and administrators, and hunt for anomalous database activity or unexpected process launches on Core servers.

8.8100% KEV
  • Ivanti Endpoint Manager (EPM) - Core server
largetens of thousands of enterprise deployments (order of ~10,000-100,000 EPM Core servers; exact install base unpublished)
CVE-2024-7593
Unauthenticated Admin Account Creation in Ivanti Virtual Traffic Manager

CVE-2024-7593 is an authentication bypass (CWE-287, CWE-303) in Ivanti Virtual Traffic Manager (vTM), Ivanti's enterprise load-balancing and traffic-management product. An unauthenticated remote attacker can send crafted requests to the vulnerable management interface and create an administrator account of their choosing, effectively obtaining full administrative control. With admin access, an attacker can modify load-balancing and traffic-routing configurations and potentially pivot further into the networks the appliance serves. Any organization running an affected Ivanti vTM release is exposed; the affected version ranges are not specified in the available data, so administrators should consult Ivanti's advisory. Exploitation is confirmed in the wild (added to CISA KEV on 2024-09-24), EPSS assigns a 100% probability of exploitation within 30 days (top percentile), CVSS is not yet scored, no public proof-of-concept is known, and ransomware use is unknown.

Do: Upgrade Virtual Traffic Manager to the fixed releases listed in Ivanti's security advisory for CVE-2024-7593; if patching is not immediately possible, follow vendor mitigations or discontinue use, as required under the CISA KEV listing (added 2024-09-24). In the meantime, restrict management-interface access to trusted networks and audit administrator accounts for unexpected or attacker-created admin entries.

9.8100% KEV
  • Ivanti Virtual Traffic Manager
moderateroughly 2,000-3,000 internet-exposed vTM instances (low thousands per public scans); total enterprise installs higher
CVE-2024-8190
OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6

Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild.

Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim.

7.289% KEV
  • Ivanti Cloud Services Appliance 4.6 through Patch 518 (versions 4.6 Patch 518 and before)
moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts)
CVE-2024-8963
Unauthenticated Path Traversal in Ivanti Cloud Services Appliance

CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets.

Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions.

9.199% KEV
  • Ivanti Cloud Services Appliance (CSA) CSA 4.6.x before 4.6 Patch 519
moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted)
Full article320 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 03, 2024Vulnerability / Endpoint Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a security flaw impacting Ivanti Endpoint Manager (EPM) that the company patched in May to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerability, tracked as CVE-2024-29824, carries a CVSS score of 9.6 out of a maximum of 10.0, indicating critical severity.

"An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code," the software service provider said in an advisory released on May 21, 2024.

Horizon3.ai, which released a proof-of-concept (PoC) exploit for the flaw in June, said the issue is rooted in a function called RecordGoodApp() within a DLL named PatchBiz.dll.

Specifically, it concerns how the function handles an SQL query statement, thereby allowing an attacker to gain remote code execution via xp_cmdshell.

The exact specifics of how the shortcoming is being exploited in the wild remains unclear, but Ivanti has since updated the bulletin to state that it has "confirmed exploitation of CVE-2024-29824" and that a "limited number of customers" have been targeted.

With the latest development, as many as four different flaws in Ivanti appliances have come under active abuse within just a month's span, showing that they are a lucrative attack vector for threat actors -

  • CVE-2024-8190 (CVSS score: 7.2) - An operating system command injection vulnerability in Cloud Service Appliance (CSA)
  • CVE-2024-8963 (CVSS score: 9.4) - A path traversal vulnerability in CSA
  • CVE-2024-7593 (CVSS score: 9.8) - An authentication bypass vulnerability Virtual Traffic Manager (vTM)

Federal agencies are mandated to update their instances to the latest version by October 23, 2024, to safeguard their networks against active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/ivanti-endpoint-manager-flaw-actively.html